• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

kubeovn / kube-ovn / 13783447535

11 Mar 2025 08:23AM UTC coverage: 22.025% (-0.006%) from 22.031%
13783447535

push

github

web-flow
feat: Improve subnet and VPC finalizer handling (#5071)

- Add finalizer to subnet and VPC resources if not present
- Remove VPC finalizer when no subnets exist
- Enhance VPC status management by adding subnets to queue when empty
- Use slices.Contains for more idiomatic finalizer checks

Signed-off-by: Mengxin Liu <liumengxinfly@gmail.com>

0 of 14 new or added lines in 2 files covered. (0.0%)

2 existing lines in 1 file now uncovered.

10263 of 46598 relevant lines covered (22.02%)

0.26 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

0.0
/pkg/controller/vpc.go
1
package controller
2

3
import (
4
        "context"
5
        "encoding/json"
6
        "errors"
7
        "fmt"
8
        "maps"
9
        "math"
10
        "net"
11
        "reflect"
12
        "slices"
13
        "sort"
14
        "strings"
15
        "time"
16

17
        v1 "k8s.io/api/core/v1"
18
        k8serrors "k8s.io/apimachinery/pkg/api/errors"
19
        metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
20
        "k8s.io/apimachinery/pkg/labels"
21
        "k8s.io/apimachinery/pkg/types"
22
        "k8s.io/client-go/tools/cache"
23
        "k8s.io/klog/v2"
24
        "sigs.k8s.io/controller-runtime/pkg/controller/controllerutil"
25

26
        kubeovnv1 "github.com/kubeovn/kube-ovn/pkg/apis/kubeovn/v1"
27
        "github.com/kubeovn/kube-ovn/pkg/ovsdb/ovnnb"
28
        "github.com/kubeovn/kube-ovn/pkg/util"
29
)
30

31
func (c *Controller) enqueueAddVpc(obj interface{}) {
×
32
        vpc := obj.(*kubeovnv1.Vpc)
×
33
        key := cache.MetaObjectToName(vpc).String()
×
34
        if _, ok := vpc.Labels[util.VpcExternalLabel]; !ok {
×
35
                klog.V(3).Infof("enqueue add vpc %s", key)
×
36
                c.addOrUpdateVpcQueue.Add(key)
×
37
        }
×
38
}
39

40
func vpcBFDPortChanged(oldObj, newObj *kubeovnv1.BFDPort) bool {
×
41
        if oldObj == nil && newObj == nil {
×
42
                return false
×
43
        }
×
44
        if oldObj == nil || newObj == nil {
×
45
                return true
×
46
        }
×
47
        return oldObj.Enabled != newObj.Enabled || oldObj.IP != newObj.IP || !reflect.DeepEqual(oldObj.NodeSelector, newObj.NodeSelector)
×
48
}
49

50
func (c *Controller) enqueueUpdateVpc(oldObj, newObj interface{}) {
×
51
        oldVpc := oldObj.(*kubeovnv1.Vpc)
×
52
        newVpc := newObj.(*kubeovnv1.Vpc)
×
53

×
54
        if !newVpc.DeletionTimestamp.IsZero() ||
×
55
                !slices.Equal(oldVpc.Spec.Namespaces, newVpc.Spec.Namespaces) ||
×
56
                !reflect.DeepEqual(oldVpc.Spec.StaticRoutes, newVpc.Spec.StaticRoutes) ||
×
57
                !reflect.DeepEqual(oldVpc.Spec.PolicyRoutes, newVpc.Spec.PolicyRoutes) ||
×
58
                !reflect.DeepEqual(oldVpc.Spec.VpcPeerings, newVpc.Spec.VpcPeerings) ||
×
59
                !maps.Equal(oldVpc.Annotations, newVpc.Annotations) ||
×
60
                !slices.Equal(oldVpc.Spec.ExtraExternalSubnets, newVpc.Spec.ExtraExternalSubnets) ||
×
61
                oldVpc.Spec.EnableExternal != newVpc.Spec.EnableExternal ||
×
62
                oldVpc.Spec.EnableBfd != newVpc.Spec.EnableBfd ||
×
63
                vpcBFDPortChanged(oldVpc.Spec.BFDPort, newVpc.Spec.BFDPort) ||
×
64
                oldVpc.Labels[util.VpcExternalLabel] != newVpc.Labels[util.VpcExternalLabel] {
×
65
                // TODO:// label VpcExternalLabel replace with spec enable external
×
66

×
67
                if newVpc.Annotations == nil {
×
68
                        newVpc.Annotations = make(map[string]string)
×
69
                }
×
70
                newVpc.Annotations[util.VpcLastPolicies] = convertPolicies(oldVpc.Spec.PolicyRoutes)
×
71

×
72
                key := cache.MetaObjectToName(newVpc).String()
×
73
                klog.Infof("enqueue update vpc %s", key)
×
74
                c.addOrUpdateVpcQueue.Add(key)
×
75
        }
76
}
77

78
func (c *Controller) enqueueDelVpc(obj interface{}) {
×
79
        vpc := obj.(*kubeovnv1.Vpc)
×
80
        if _, ok := vpc.Labels[util.VpcExternalLabel]; !vpc.Status.Default || !ok {
×
81
                klog.V(3).Infof("enqueue delete vpc %s", vpc.Name)
×
82
                c.delVpcQueue.Add(vpc)
×
83
        }
×
84
}
85

86
func (c *Controller) handleDelVpc(vpc *kubeovnv1.Vpc) error {
×
87
        c.vpcKeyMutex.LockKey(vpc.Name)
×
88
        defer func() { _ = c.vpcKeyMutex.UnlockKey(vpc.Name) }()
×
89
        klog.Infof("handle delete vpc %s", vpc.Name)
×
90

×
91
        // should delete vpc subnets first
×
92
        var err error
×
93
        for _, subnet := range vpc.Status.Subnets {
×
94
                if _, err = c.subnetsLister.Get(subnet); err != nil {
×
95
                        if k8serrors.IsNotFound(err) {
×
96
                                continue
×
97
                        }
98
                        err = fmt.Errorf("failed to get subnet %s for vpc %s: %w", subnet, vpc.Name, err)
×
99
                } else {
×
100
                        err = fmt.Errorf("failed to delete vpc %s, please delete subnet %s first", vpc.Name, subnet)
×
101
                }
×
102
                klog.Error(err)
×
103
                return err
×
104
        }
105

106
        if err := c.deleteVpcLb(vpc); err != nil {
×
107
                klog.Error(err)
×
108
                return err
×
109
        }
×
110

111
        if err := c.handleDelVpcExternalSubnet(vpc.Name, c.config.ExternalGatewaySwitch); err != nil {
×
112
                klog.Errorf("failed to delete external connection for vpc %s, error %v", vpc.Name, err)
×
113
                return err
×
114
        }
×
115

116
        for _, subnet := range vpc.Status.ExtraExternalSubnets {
×
117
                klog.Infof("disconnect external network %s to vpc %s", subnet, vpc.Name)
×
118
                if err := c.handleDelVpcExternalSubnet(vpc.Name, subnet); err != nil {
×
119
                        klog.Error(err)
×
120
                        return err
×
121
                }
×
122
        }
123

124
        if err := c.deleteVpcRouter(vpc.Status.Router); err != nil {
×
125
                klog.Error(err)
×
126
                return err
×
127
        }
×
128

129
        return nil
×
130
}
131

132
func (c *Controller) handleUpdateVpcStatus(key string) error {
×
133
        c.vpcKeyMutex.LockKey(key)
×
134
        defer func() { _ = c.vpcKeyMutex.UnlockKey(key) }()
×
135
        klog.Infof("handle status update for vpc %s", key)
×
136

×
137
        cachedVpc, err := c.vpcsLister.Get(key)
×
138
        if err != nil {
×
139
                if k8serrors.IsNotFound(err) {
×
140
                        return nil
×
141
                }
×
142
                klog.Error(err)
×
143
                return err
×
144
        }
145
        vpc := cachedVpc.DeepCopy()
×
146

×
147
        subnets, defaultSubnet, err := c.getVpcSubnets(vpc)
×
148
        if err != nil {
×
149
                klog.Error(err)
×
150
                return err
×
151
        }
×
152

153
        change := false
×
154
        if vpc.Status.DefaultLogicalSwitch != defaultSubnet {
×
155
                change = true
×
156
        }
×
157

158
        vpc.Status.DefaultLogicalSwitch = defaultSubnet
×
159
        vpc.Status.Subnets = subnets
×
NEW
160

×
161
        if !vpc.Spec.BFDPort.IsEnabled() && !vpc.Status.BFDPort.IsEmpty() {
×
162
                vpc.Status.BFDPort.Clear()
×
163
        }
×
164
        bytes, err := vpc.Status.Bytes()
×
165
        if err != nil {
×
166
                klog.Error(err)
×
167
                return err
×
168
        }
×
169

170
        vpc, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Patch(context.Background(), vpc.Name, types.MergePatchType, bytes, metav1.PatchOptions{}, "status")
×
171
        if err != nil {
×
172
                klog.Error(err)
×
173
                return err
×
174
        }
×
175

NEW
176
        if len(vpc.Status.Subnets) == 0 {
×
NEW
177
                klog.Infof("vpc %s has no subnets, add to queue", vpc.Name)
×
NEW
178
                c.addOrUpdateVpcQueue.AddAfter(vpc.Name, 5*time.Second)
×
NEW
179
        }
×
180

181
        if change {
×
182
                for _, ns := range vpc.Spec.Namespaces {
×
183
                        c.addNamespaceQueue.Add(ns)
×
184
                }
×
185
        }
186

187
        natGws, err := c.vpcNatGatewayLister.List(labels.Everything())
×
188
        if err != nil {
×
189
                klog.Error(err)
×
190
                return err
×
191
        }
×
192
        for _, gw := range natGws {
×
193
                if key == gw.Spec.Vpc {
×
194
                        c.updateVpcSubnetQueue.Add(gw.Name)
×
195
                }
×
196
        }
197
        return nil
×
198
}
199

200
type VpcLoadBalancer struct {
201
        TCPLoadBalancer      string
202
        TCPSessLoadBalancer  string
203
        UDPLoadBalancer      string
204
        UDPSessLoadBalancer  string
205
        SctpLoadBalancer     string
206
        SctpSessLoadBalancer string
207
}
208

209
func (c *Controller) GenVpcLoadBalancer(vpcKey string) *VpcLoadBalancer {
×
210
        if vpcKey == c.config.ClusterRouter || vpcKey == "" {
×
211
                return &VpcLoadBalancer{
×
212
                        TCPLoadBalancer:      c.config.ClusterTCPLoadBalancer,
×
213
                        TCPSessLoadBalancer:  c.config.ClusterTCPSessionLoadBalancer,
×
214
                        UDPLoadBalancer:      c.config.ClusterUDPLoadBalancer,
×
215
                        UDPSessLoadBalancer:  c.config.ClusterUDPSessionLoadBalancer,
×
216
                        SctpLoadBalancer:     c.config.ClusterSctpLoadBalancer,
×
217
                        SctpSessLoadBalancer: c.config.ClusterSctpSessionLoadBalancer,
×
218
                }
×
219
        }
×
220
        return &VpcLoadBalancer{
×
221
                TCPLoadBalancer:      fmt.Sprintf("vpc-%s-tcp-load", vpcKey),
×
222
                TCPSessLoadBalancer:  fmt.Sprintf("vpc-%s-tcp-sess-load", vpcKey),
×
223
                UDPLoadBalancer:      fmt.Sprintf("vpc-%s-udp-load", vpcKey),
×
224
                UDPSessLoadBalancer:  fmt.Sprintf("vpc-%s-udp-sess-load", vpcKey),
×
225
                SctpLoadBalancer:     fmt.Sprintf("vpc-%s-sctp-load", vpcKey),
×
226
                SctpSessLoadBalancer: fmt.Sprintf("vpc-%s-sctp-sess-load", vpcKey),
×
227
        }
×
228
}
229

230
func (c *Controller) addLoadBalancer(vpc string) (*VpcLoadBalancer, error) {
×
231
        vpcLbConfig := c.GenVpcLoadBalancer(vpc)
×
232
        if err := c.initLB(vpcLbConfig.TCPLoadBalancer, string(v1.ProtocolTCP), false); err != nil {
×
233
                return nil, err
×
234
        }
×
235
        if err := c.initLB(vpcLbConfig.TCPSessLoadBalancer, string(v1.ProtocolTCP), true); err != nil {
×
236
                return nil, err
×
237
        }
×
238
        if err := c.initLB(vpcLbConfig.UDPLoadBalancer, string(v1.ProtocolUDP), false); err != nil {
×
239
                return nil, err
×
240
        }
×
241
        if err := c.initLB(vpcLbConfig.UDPSessLoadBalancer, string(v1.ProtocolUDP), true); err != nil {
×
242
                return nil, err
×
243
        }
×
244
        if err := c.initLB(vpcLbConfig.SctpLoadBalancer, string(v1.ProtocolSCTP), false); err != nil {
×
245
                return nil, err
×
246
        }
×
247
        if err := c.initLB(vpcLbConfig.SctpSessLoadBalancer, string(v1.ProtocolSCTP), true); err != nil {
×
248
                return nil, err
×
249
        }
×
250

251
        return vpcLbConfig, nil
×
252
}
253

254
func (c *Controller) handleAddOrUpdateVpc(key string) error {
×
255
        c.vpcKeyMutex.LockKey(key)
×
256
        defer func() { _ = c.vpcKeyMutex.UnlockKey(key) }()
×
257
        klog.Infof("handle add/update vpc %s", key)
×
258

×
259
        cachedVpc, err := c.vpcsLister.Get(key)
×
260
        if err != nil {
×
261
                if k8serrors.IsNotFound(err) {
×
262
                        return nil
×
263
                }
×
264
                klog.Error(err)
×
265
                return err
×
266
        }
267

268
        vpc, err := c.formatVpc(cachedVpc.DeepCopy())
×
269
        if err != nil {
×
270
                klog.Errorf("failed to format vpc %s: %v", key, err)
×
271
                return err
×
272
        }
×
273

274
        if err = c.createVpcRouter(key); err != nil {
×
275
                klog.Errorf("failed to create vpc router for vpc %s: %v", key, err)
×
276
                return err
×
277
        }
×
278

279
        var newPeers []string
×
280
        for _, peering := range vpc.Spec.VpcPeerings {
×
281
                if err = util.CheckCidrs(peering.LocalConnectIP); err != nil {
×
282
                        klog.Errorf("invalid cidr %s", peering.LocalConnectIP)
×
283
                        return err
×
284
                }
×
285

286
                newPeers = append(newPeers, peering.RemoteVpc)
×
287
                if err := c.OVNNbClient.CreatePeerRouterPort(vpc.Name, peering.RemoteVpc, peering.LocalConnectIP); err != nil {
×
288
                        klog.Errorf("create peer router port for vpc %s, %v", vpc.Name, err)
×
289
                        return err
×
290
                }
×
291
        }
292
        for _, oldPeer := range vpc.Status.VpcPeerings {
×
293
                if !slices.Contains(newPeers, oldPeer) {
×
294
                        if err = c.OVNNbClient.DeleteLogicalRouterPort(fmt.Sprintf("%s-%s", vpc.Name, oldPeer)); err != nil {
×
295
                                klog.Errorf("delete peer router port for vpc %s, %v", vpc.Name, err)
×
296
                                return err
×
297
                        }
×
298
                }
299
        }
300

301
        // handle static route
302
        var (
×
303
                staticExistedRoutes []*ovnnb.LogicalRouterStaticRoute
×
304
                staticTargetRoutes  []*kubeovnv1.StaticRoute
×
305
                staticRouteMapping  map[string][]*kubeovnv1.StaticRoute
×
306
        )
×
307

×
308
        staticExistedRoutes, err = c.OVNNbClient.ListLogicalRouterStaticRoutes(vpc.Name, nil, nil, "", nil)
×
309
        if err != nil {
×
310
                klog.Errorf("failed to get vpc %s static route list, %v", vpc.Name, err)
×
311
                return err
×
312
        }
×
313

314
        var externalSubnet *kubeovnv1.Subnet
×
315
        externalSubnetExist := false
×
316
        if c.config.EnableEipSnat {
×
317
                externalSubnet, err = c.subnetsLister.Get(c.config.ExternalGatewaySwitch)
×
318
                if err != nil {
×
319
                        klog.Warningf("enable-eip-snat need external subnet %s to be exist: %v", c.config.ExternalGatewaySwitch, err)
×
320
                } else {
×
321
                        externalSubnetExist = true
×
322
                }
×
323
        }
324

325
        staticRouteMapping = c.getRouteTablesByVpc(vpc)
×
326
        staticTargetRoutes = vpc.Spec.StaticRoutes
×
327
        if vpc.Name == c.config.ClusterRouter {
×
328
                if _, ok := staticRouteMapping[util.MainRouteTable]; !ok {
×
329
                        staticRouteMapping[util.MainRouteTable] = nil
×
330
                }
×
331

332
                joinSubnet, err := c.subnetsLister.Get(c.config.NodeSwitch)
×
333
                if err != nil {
×
334
                        if !k8serrors.IsNotFound(err) {
×
335
                                klog.Errorf("failed to get node switch subnet %s: %v", c.config.NodeSwitch, err)
×
336
                                return err
×
337
                        }
×
338
                        c.addOrUpdateVpcQueue.Add(vpc.Name)
×
339
                        return nil
×
340
                }
341
                gatewayV4, gatewayV6 := util.SplitStringIP(joinSubnet.Spec.Gateway)
×
342
                if gatewayV4 != "" {
×
343
                        for table := range staticRouteMapping {
×
344
                                staticTargetRoutes = append(
×
345
                                        staticTargetRoutes,
×
346
                                        &kubeovnv1.StaticRoute{
×
347
                                                Policy:     kubeovnv1.PolicyDst,
×
348
                                                CIDR:       "0.0.0.0/0",
×
349
                                                NextHopIP:  gatewayV4,
×
350
                                                RouteTable: table,
×
351
                                        },
×
352
                                )
×
353
                        }
×
354
                }
355
                if gatewayV6 != "" {
×
356
                        for table := range staticRouteMapping {
×
357
                                staticTargetRoutes = append(
×
358
                                        staticTargetRoutes,
×
359
                                        &kubeovnv1.StaticRoute{
×
360
                                                Policy:     kubeovnv1.PolicyDst,
×
361
                                                CIDR:       "::/0",
×
362
                                                NextHopIP:  gatewayV6,
×
363
                                                RouteTable: table,
×
364
                                        },
×
365
                                )
×
366
                        }
×
367
                }
368
                if c.config.EnableEipSnat {
×
369
                        cm, err := c.configMapsLister.ConfigMaps(c.config.ExternalGatewayConfigNS).Get(util.ExternalGatewayConfig)
×
370
                        if err == nil {
×
371
                                nextHop := cm.Data["external-gw-addr"]
×
372
                                if nextHop == "" {
×
373
                                        if !externalSubnetExist {
×
374
                                                err = fmt.Errorf("failed to get external subnet %s", c.config.ExternalGatewaySwitch)
×
375
                                                klog.Error(err)
×
376
                                                return err
×
377
                                        }
×
378
                                        nextHop = externalSubnet.Spec.Gateway
×
379
                                        if nextHop == "" {
×
380
                                                klog.Errorf("no available gateway address")
×
381
                                                return errors.New("no available gateway address")
×
382
                                        }
×
383
                                }
384
                                if strings.Contains(nextHop, "/") {
×
385
                                        nextHop = strings.Split(nextHop, "/")[0]
×
386
                                }
×
387

388
                                lr, err := c.OVNNbClient.GetLogicalRouter(vpc.Name, false)
×
389
                                if err != nil {
×
390
                                        klog.Errorf("failed to get logical router %s: %v", vpc.Name, err)
×
391
                                        return err
×
392
                                }
×
393

394
                                for _, nat := range lr.Nat {
×
395
                                        info, err := c.OVNNbClient.GetNATByUUID(nat)
×
396
                                        if err != nil {
×
397
                                                klog.Errorf("failed to get nat ip info for vpc %s, %v", vpc.Name, err)
×
398
                                                return err
×
399
                                        }
×
400
                                        if info.LogicalIP != "" {
×
401
                                                for table := range staticRouteMapping {
×
402
                                                        staticTargetRoutes = append(
×
403
                                                                staticTargetRoutes,
×
404
                                                                &kubeovnv1.StaticRoute{
×
405
                                                                        Policy:     kubeovnv1.PolicySrc,
×
406
                                                                        CIDR:       info.LogicalIP,
×
407
                                                                        NextHopIP:  nextHop,
×
408
                                                                        RouteTable: table,
×
409
                                                                },
×
410
                                                        )
×
411
                                                }
×
412
                                        }
413
                                }
414
                        }
415
                }
416
        }
417

418
        routeNeedDel, routeNeedAdd, err := diffStaticRoute(staticExistedRoutes, staticTargetRoutes)
×
419
        if err != nil {
×
420
                klog.Errorf("failed to diff vpc %s static route, %v", vpc.Name, err)
×
421
                return err
×
422
        }
×
423

424
        for _, item := range routeNeedDel {
×
425
                klog.Infof("vpc %s del static route: %+v", vpc.Name, item)
×
426
                policy := convertPolicy(item.Policy)
×
427
                if err = c.OVNNbClient.DeleteLogicalRouterStaticRoute(vpc.Name, &item.RouteTable, &policy, item.CIDR, item.NextHopIP); err != nil {
×
428
                        klog.Errorf("del vpc %s static route failed, %v", vpc.Name, err)
×
429
                        return err
×
430
                }
×
431
        }
432

433
        for _, item := range routeNeedAdd {
×
434
                if item.BfdID != "" {
×
435
                        klog.Infof("vpc %s add static ecmp route: %+v", vpc.Name, item)
×
436
                        if err = c.OVNNbClient.AddLogicalRouterStaticRoute(
×
437
                                vpc.Name, item.RouteTable, convertPolicy(item.Policy), item.CIDR, &item.BfdID, nil, item.NextHopIP,
×
438
                        ); err != nil {
×
439
                                klog.Errorf("failed to add bfd static route to vpc %s , %v", vpc.Name, err)
×
440
                                return err
×
441
                        }
×
442
                } else {
×
443
                        klog.Infof("vpc %s add static route: %+v", vpc.Name, item)
×
444
                        if err = c.OVNNbClient.AddLogicalRouterStaticRoute(
×
445
                                vpc.Name, item.RouteTable, convertPolicy(item.Policy), item.CIDR, nil, nil, item.NextHopIP,
×
446
                        ); err != nil {
×
447
                                klog.Errorf("failed to add normal static route to vpc %s , %v", vpc.Name, err)
×
448
                                return err
×
449
                        }
×
450
                }
451
        }
452

453
        // handle policy route
454
        var (
×
455
                policyRouteExisted, policyRouteNeedDel, policyRouteNeedAdd []*kubeovnv1.PolicyRoute
×
456
                policyRouteLogical                                         []*ovnnb.LogicalRouterPolicy
×
457
                externalIDs                                                = map[string]string{"vendor": util.CniTypeName}
×
458
        )
×
459

×
460
        if vpc.Name == c.config.ClusterRouter {
×
461
                policyRouteExisted = reversePolicies(vpc.Annotations[util.VpcLastPolicies])
×
462
                // diff list
×
463
                policyRouteNeedDel, policyRouteNeedAdd = diffPolicyRouteWithExisted(policyRouteExisted, vpc.Spec.PolicyRoutes)
×
464
        } else {
×
465
                if vpc.Spec.PolicyRoutes == nil {
×
466
                        // do not clean default vpc policy routes
×
467
                        if err = c.OVNNbClient.ClearLogicalRouterPolicy(vpc.Name); err != nil {
×
468
                                klog.Errorf("clean all vpc %s policy route failed, %v", vpc.Name, err)
×
469
                                return err
×
470
                        }
×
471
                } else {
×
472
                        policyRouteLogical, err = c.OVNNbClient.ListLogicalRouterPolicies(vpc.Name, -1, nil, true)
×
473
                        if err != nil {
×
474
                                klog.Errorf("failed to get vpc %s policy route list, %v", vpc.Name, err)
×
475
                                return err
×
476
                        }
×
477
                        // diff vpc policy route
478
                        policyRouteNeedDel, policyRouteNeedAdd = diffPolicyRouteWithLogical(policyRouteLogical, vpc.Spec.PolicyRoutes)
×
479
                }
480
        }
481
        // delete policies non-exist
482
        for _, item := range policyRouteNeedDel {
×
483
                klog.Infof("delete policy route for router: %s, priority: %d, match %s", vpc.Name, item.Priority, item.Match)
×
484
                if err = c.OVNNbClient.DeleteLogicalRouterPolicy(vpc.Name, item.Priority, item.Match); err != nil {
×
485
                        klog.Errorf("del vpc %s policy route failed, %v", vpc.Name, err)
×
486
                        return err
×
487
                }
×
488
        }
489
        // add new policies
490
        for _, item := range policyRouteNeedAdd {
×
491
                klog.Infof("add policy route for router: %s, match %s, action %s, nexthop %s, externalID %v", c.config.ClusterRouter, item.Match, string(item.Action), item.NextHopIP, externalIDs)
×
492
                if err = c.OVNNbClient.AddLogicalRouterPolicy(vpc.Name, item.Priority, item.Match, string(item.Action), []string{item.NextHopIP}, nil, externalIDs); err != nil {
×
493
                        klog.Errorf("add policy route to vpc %s failed, %v", vpc.Name, err)
×
494
                        return err
×
495
                }
×
496
        }
497

498
        vpc.Status.Router = key
×
499
        vpc.Status.Standby = true
×
500
        vpc.Status.VpcPeerings = newPeers
×
501
        if c.config.EnableLb {
×
502
                vpcLb, err := c.addLoadBalancer(key)
×
503
                if err != nil {
×
504
                        klog.Error(err)
×
505
                        return err
×
506
                }
×
507
                vpc.Status.TCPLoadBalancer = vpcLb.TCPLoadBalancer
×
508
                vpc.Status.TCPSessionLoadBalancer = vpcLb.TCPSessLoadBalancer
×
509
                vpc.Status.UDPLoadBalancer = vpcLb.UDPLoadBalancer
×
510
                vpc.Status.UDPSessionLoadBalancer = vpcLb.UDPSessLoadBalancer
×
511
                vpc.Status.SctpLoadBalancer = vpcLb.SctpLoadBalancer
×
512
                vpc.Status.SctpSessionLoadBalancer = vpcLb.SctpSessLoadBalancer
×
513
        }
514
        bytes, err := vpc.Status.Bytes()
×
515
        if err != nil {
×
516
                klog.Error(err)
×
517
                return err
×
518
        }
×
519
        vpc, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Patch(context.Background(), vpc.Name, types.MergePatchType, bytes, metav1.PatchOptions{}, "status")
×
520
        if err != nil {
×
521
                klog.Error(err)
×
522
                return err
×
523
        }
×
524

525
        if len(vpc.Annotations) != 0 && strings.ToLower(vpc.Annotations[util.VpcLbAnnotation]) == "on" {
×
526
                if err = c.createVpcLb(vpc); err != nil {
×
527
                        klog.Error(err)
×
528
                        return err
×
529
                }
×
530
        } else if err = c.deleteVpcLb(vpc); err != nil {
×
531
                klog.Error(err)
×
532
                return err
×
533
        }
×
534

535
        subnets, err := c.subnetsLister.List(labels.Everything())
×
536
        if err != nil {
×
537
                klog.Error(err)
×
538
                return err
×
539
        }
×
540
        custVpcEnableExternalMultiHopEcmp := false
×
541
        for _, subnet := range subnets {
×
542
                if subnet.Spec.Vpc == key {
×
543
                        c.addOrUpdateSubnetQueue.Add(subnet.Name)
×
544
                        if vpc.Name != util.DefaultVpc && vpc.Spec.EnableBfd && subnet.Spec.EnableEcmp {
×
545
                                custVpcEnableExternalMultiHopEcmp = true
×
546
                        }
×
547
                }
548
        }
549

550
        if vpc.Name != util.DefaultVpc {
×
551
                if cachedVpc.Spec.EnableExternal {
×
552
                        if !externalSubnetExist {
×
553
                                err = fmt.Errorf("failed to get external subnet %s", c.config.ExternalGatewaySwitch)
×
554
                                klog.Error(err)
×
555
                                return err
×
556
                        }
×
557
                        if externalSubnet.Spec.LogicalGateway {
×
558
                                klog.Infof("no need to handle external connection for logical gw external subnet %s", c.config.ExternalGatewaySwitch)
×
559
                                return nil
×
560
                        }
×
561
                        if !cachedVpc.Status.EnableExternal {
×
562
                                // connect vpc to default external
×
563
                                klog.Infof("connect external network with vpc %s", vpc.Name)
×
564
                                if err := c.handleAddVpcExternalSubnet(key, c.config.ExternalGatewaySwitch); err != nil {
×
565
                                        klog.Errorf("failed to add default external connection for vpc %s, error %v", key, err)
×
566
                                        return err
×
567
                                }
×
568
                        }
569
                        if vpc.Spec.EnableBfd {
×
570
                                // create bfd between lrp and physical switch gw
×
571
                                // bfd status down means current lrp binding chassis node external nic lost external network connectivity
×
572
                                // should switch lrp to another node
×
573
                                lrpEipName := fmt.Sprintf("%s-%s", key, c.config.ExternalGatewaySwitch)
×
574
                                v4ExtGw, _ := util.SplitStringIP(externalSubnet.Spec.Gateway)
×
575
                                // TODO: dualstack
×
576
                                if _, err := c.OVNNbClient.CreateBFD(lrpEipName, v4ExtGw, c.config.BfdMinRx, c.config.BfdMinTx, c.config.BfdDetectMult, nil); err != nil {
×
577
                                        klog.Error(err)
×
578
                                        return err
×
579
                                }
×
580
                                // TODO: support multi external nic
581
                                if custVpcEnableExternalMultiHopEcmp {
×
582
                                        klog.Infof("remove normal static ecmp route for vpc %s", vpc.Name)
×
583
                                        // auto remove normal type static route, if using ecmp based bfd
×
584
                                        if err := c.reconcileCustomVpcDelNormalStaticRoute(vpc.Name); err != nil {
×
585
                                                klog.Errorf("failed to reconcile del vpc %q normal static route", vpc.Name)
×
586
                                                return err
×
587
                                        }
×
588
                                }
589
                        }
590
                        if cachedVpc.Spec.ExtraExternalSubnets != nil {
×
591
                                sort.Strings(vpc.Spec.ExtraExternalSubnets)
×
592
                        }
×
593
                        // add external subnets only in spec and delete external subnets only in status
594
                        if !slices.Equal(vpc.Spec.ExtraExternalSubnets, vpc.Status.ExtraExternalSubnets) {
×
595
                                for _, subnetStatus := range cachedVpc.Status.ExtraExternalSubnets {
×
596
                                        if !slices.Contains(cachedVpc.Spec.ExtraExternalSubnets, subnetStatus) {
×
597
                                                klog.Infof("delete external subnet %s connection for vpc %s", subnetStatus, vpc.Name)
×
598
                                                if err := c.handleDelVpcExternalSubnet(vpc.Name, subnetStatus); err != nil {
×
599
                                                        klog.Errorf("failed to delete external subnet %s connection for vpc %s, error %v", subnetStatus, vpc.Name, err)
×
600
                                                        return err
×
601
                                                }
×
602
                                        }
603
                                }
604
                                for _, subnetSpec := range cachedVpc.Spec.ExtraExternalSubnets {
×
605
                                        if !slices.Contains(cachedVpc.Status.ExtraExternalSubnets, subnetSpec) {
×
606
                                                klog.Infof("connect external subnet %s with vpc %s", subnetSpec, vpc.Name)
×
607
                                                if err := c.handleAddVpcExternalSubnet(key, subnetSpec); err != nil {
×
608
                                                        klog.Errorf("failed to add external subnet %s connection for vpc %s, error %v", subnetSpec, key, err)
×
609
                                                        return err
×
610
                                                }
×
611
                                        }
612
                                }
613
                                if err := c.updateVpcAddExternalStatus(key, true); err != nil {
×
614
                                        klog.Errorf("failed to update additional external subnets status, %v", err)
×
615
                                        return err
×
616
                                }
×
617
                        }
618
                }
619

620
                if !cachedVpc.Spec.EnableBfd && cachedVpc.Status.EnableBfd {
×
621
                        lrpEipName := fmt.Sprintf("%s-%s", key, c.config.ExternalGatewaySwitch)
×
622
                        if err := c.OVNNbClient.DeleteBFDByDstIP(lrpEipName, ""); err != nil {
×
623
                                klog.Error(err)
×
624
                                return err
×
625
                        }
×
626
                        if err := c.handleDeleteVpcStaticRoute(key); err != nil {
×
627
                                klog.Errorf("failed to delete bfd route for vpc %s, error %v", key, err)
×
628
                                return err
×
629
                        }
×
630
                }
631

632
                if !cachedVpc.Spec.EnableExternal && cachedVpc.Status.EnableExternal {
×
633
                        // disconnect vpc to default external
×
634
                        if err := c.handleDelVpcExternalSubnet(key, c.config.ExternalGatewaySwitch); err != nil {
×
635
                                klog.Errorf("failed to delete external connection for vpc %s, error %v", key, err)
×
636
                                return err
×
637
                        }
×
638
                }
639

640
                if cachedVpc.Status.ExtraExternalSubnets != nil && !cachedVpc.Spec.EnableExternal {
×
641
                        // disconnect vpc to extra external subnets
×
642
                        for _, subnet := range cachedVpc.Status.ExtraExternalSubnets {
×
643
                                klog.Infof("disconnect external network %s to vpc %s", subnet, vpc.Name)
×
644
                                if err := c.handleDelVpcExternalSubnet(key, subnet); err != nil {
×
645
                                        klog.Error(err)
×
646
                                        return err
×
647
                                }
×
648
                        }
649
                        if err := c.updateVpcAddExternalStatus(key, false); err != nil {
×
650
                                klog.Errorf("failed to update additional external subnets status, %v", err)
×
651
                                return err
×
652
                        }
×
653
                }
654
        }
655

656
        bfdPortName, bfdPortNodes, err := c.reconcileVpcBfdLRP(vpc)
×
657
        if err != nil {
×
658
                klog.Error(err)
×
659
                return err
×
660
        }
×
661
        if vpc.Spec.BFDPort == nil || !vpc.Spec.BFDPort.Enabled {
×
662
                vpc.Status.BFDPort = kubeovnv1.BFDPortStatus{}
×
663
        } else {
×
664
                vpc.Status.BFDPort = kubeovnv1.BFDPortStatus{
×
665
                        Name:  bfdPortName,
×
666
                        IP:    vpc.Spec.BFDPort.IP,
×
667
                        Nodes: bfdPortNodes,
×
668
                }
×
669
        }
×
670
        if _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().
×
671
                UpdateStatus(context.Background(), vpc, metav1.UpdateOptions{}); err != nil {
×
672
                klog.Error(err)
×
673
                return err
×
674
        }
×
675

676
        return nil
×
677
}
678

679
func (c *Controller) reconcileVpcBfdLRP(vpc *kubeovnv1.Vpc) (string, []string, error) {
×
680
        portName := "bfd@" + vpc.Name
×
681
        if vpc.Spec.BFDPort == nil || !vpc.Spec.BFDPort.Enabled {
×
682
                if err := c.OVNNbClient.DeleteLogicalRouterPort(portName); err != nil {
×
683
                        err = fmt.Errorf("failed to delete BFD LRP %s: %w", portName, err)
×
684
                        klog.Error(err)
×
685
                        return portName, nil, err
×
686
                }
×
687
                if err := c.OVNNbClient.DeleteHAChassisGroup(portName); err != nil {
×
688
                        err = fmt.Errorf("failed to delete HA chassis group %s: %w", portName, err)
×
689
                        klog.Error(err)
×
690
                        return portName, nil, err
×
691
                }
×
692
                return portName, nil, nil
×
693
        }
694

695
        var err error
×
696
        chassisCount := 3
×
697
        selector := labels.Everything()
×
698
        if vpc.Spec.BFDPort.NodeSelector != nil {
×
699
                chassisCount = math.MaxInt
×
700
                if selector, err = metav1.LabelSelectorAsSelector(vpc.Spec.BFDPort.NodeSelector); err != nil {
×
701
                        err = fmt.Errorf("failed to parse node selector %q: %w", vpc.Spec.BFDPort.NodeSelector.String(), err)
×
702
                        klog.Error(err)
×
703
                        return portName, nil, err
×
704
                }
×
705
        }
706

707
        nodes, err := c.nodesLister.List(selector)
×
708
        if err != nil {
×
709
                err = fmt.Errorf("failed to list nodes with selector %q: %w", vpc.Spec.BFDPort.NodeSelector, err)
×
710
                klog.Error(err)
×
711
                return portName, nil, err
×
712
        }
×
713
        if len(nodes) == 0 {
×
714
                err = fmt.Errorf("no nodes found by selector %q", selector.String())
×
715
                klog.Error(err)
×
716
                return portName, nil, err
×
717
        }
×
718

719
        nodeNames := make([]string, 0, len(nodes))
×
720
        chassisCount = min(chassisCount, len(nodes))
×
721
        chassisNames := make([]string, 0, chassisCount)
×
722
        for _, nodes := range nodes[:chassisCount] {
×
723
                chassis, err := c.OVNSbClient.GetChassisByHost(nodes.Name)
×
724
                if err != nil {
×
725
                        err = fmt.Errorf("failed to get chassis of node %s: %w", nodes.Name, err)
×
726
                        klog.Error(err)
×
727
                        return portName, nil, err
×
728
                }
×
729
                chassisNames = append(chassisNames, chassis.Name)
×
730
                nodeNames = append(nodeNames, nodes.Name)
×
731
        }
732

733
        networks := strings.Split(vpc.Spec.BFDPort.IP, ",")
×
734
        if err = c.OVNNbClient.CreateLogicalRouterPort(vpc.Name, portName, "", networks); err != nil {
×
735
                klog.Error(err)
×
736
                return portName, nil, err
×
737
        }
×
738
        if err = c.OVNNbClient.UpdateLogicalRouterPortNetworks(portName, networks); err != nil {
×
739
                klog.Error(err)
×
740
                return portName, nil, err
×
741
        }
×
742
        if err = c.OVNNbClient.UpdateLogicalRouterPortOptions(portName, map[string]string{"bfd-only": "true"}); err != nil {
×
743
                klog.Error(err)
×
744
                return portName, nil, err
×
745
        }
×
746
        if err = c.OVNNbClient.CreateHAChassisGroup(portName, chassisNames, map[string]string{"lrp": portName}); err != nil {
×
747
                klog.Error(err)
×
748
                return portName, nil, err
×
749
        }
×
750
        if err = c.OVNNbClient.SetLogicalRouterPortHAChassisGroup(portName, portName); err != nil {
×
751
                klog.Error(err)
×
752
                return portName, nil, err
×
753
        }
×
754

755
        return portName, nodeNames, nil
×
756
}
757

758
func (c *Controller) addPolicyRouteToVpc(vpcName string, policy *kubeovnv1.PolicyRoute, externalIDs map[string]string) error {
×
759
        var (
×
760
                nextHops []string
×
761
                err      error
×
762
        )
×
763

×
764
        if policy.NextHopIP != "" {
×
765
                nextHops = strings.Split(policy.NextHopIP, ",")
×
766
        }
×
767

768
        if err = c.OVNNbClient.AddLogicalRouterPolicy(vpcName, policy.Priority, policy.Match, string(policy.Action), nextHops, nil, externalIDs); err != nil {
×
769
                klog.Errorf("add policy route to vpc %s failed, %v", vpcName, err)
×
770
                return err
×
771
        }
×
772
        return nil
×
773
}
774

775
func buildExternalIDsMapKey(match, action string, priority int) string {
×
776
        return fmt.Sprintf("%s-%s-%d", match, action, priority)
×
777
}
×
778

779
func (c *Controller) batchAddPolicyRouteToVpc(name string, policies []*kubeovnv1.PolicyRoute, externalIDs map[string]map[string]string) error {
×
780
        if len(policies) == 0 {
×
781
                return nil
×
782
        }
×
783
        start := time.Now()
×
784
        routerPolicies := make([]*ovnnb.LogicalRouterPolicy, 0, len(policies))
×
785
        for _, policy := range policies {
×
786
                var nextHops []string
×
787
                if policy.NextHopIP != "" {
×
788
                        nextHops = strings.Split(policy.NextHopIP, ",")
×
789
                }
×
790
                routerPolicies = append(routerPolicies, &ovnnb.LogicalRouterPolicy{
×
791
                        Priority:    policy.Priority,
×
792
                        Nexthops:    nextHops,
×
793
                        Action:      string(policy.Action),
×
794
                        Match:       policy.Match,
×
795
                        ExternalIDs: externalIDs[buildExternalIDsMapKey(policy.Match, string(policy.Action), policy.Priority)],
×
796
                })
×
797
        }
798

799
        if err := c.OVNNbClient.BatchAddLogicalRouterPolicy(name, routerPolicies...); err != nil {
×
800
                klog.Errorf("batch add policy route to vpc %s failed, %v", name, err)
×
801
                return err
×
802
        }
×
803
        klog.Infof("take to %v batch add policy route to vpc %s policies %d", time.Since(start), name, len(policies))
×
804
        return nil
×
805
}
806

807
func (c *Controller) deletePolicyRouteFromVpc(vpcName string, priority int, match string) error {
×
808
        var (
×
809
                vpc, cachedVpc *kubeovnv1.Vpc
×
810
                err            error
×
811
        )
×
812

×
813
        if err = c.OVNNbClient.DeleteLogicalRouterPolicy(vpcName, priority, match); err != nil {
×
814
                klog.Error(err)
×
815
                return err
×
816
        }
×
817

818
        cachedVpc, err = c.vpcsLister.Get(vpcName)
×
819
        if err != nil {
×
820
                if k8serrors.IsNotFound(err) {
×
821
                        return nil
×
822
                }
×
823
                klog.Error(err)
×
824
                return err
×
825
        }
826
        vpc = cachedVpc.DeepCopy()
×
827
        // make sure custom policies not be deleted
×
828
        _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Update(context.Background(), vpc, metav1.UpdateOptions{})
×
829
        if err != nil {
×
830
                klog.Error(err)
×
831
                return err
×
832
        }
×
833
        return nil
×
834
}
835

836
func (c *Controller) batchDeletePolicyRouteFromVpc(name string, policies []*kubeovnv1.PolicyRoute) error {
×
837
        var (
×
838
                vpc, cachedVpc *kubeovnv1.Vpc
×
839
                err            error
×
840
        )
×
841

×
842
        start := time.Now()
×
843
        routerPolicies := make([]*ovnnb.LogicalRouterPolicy, 0, len(policies))
×
844
        for _, policy := range policies {
×
845
                routerPolicies = append(routerPolicies, &ovnnb.LogicalRouterPolicy{
×
846
                        Priority: policy.Priority,
×
847
                        Match:    policy.Match,
×
848
                })
×
849
        }
×
850

851
        if err = c.OVNNbClient.BatchDeleteLogicalRouterPolicy(name, routerPolicies); err != nil {
×
852
                return err
×
853
        }
×
854
        klog.V(3).Infof("take to %v batch delete policy route from vpc %s policies %d", time.Since(start), name, len(policies))
×
855

×
856
        cachedVpc, err = c.vpcsLister.Get(name)
×
857
        if err != nil {
×
858
                if k8serrors.IsNotFound(err) {
×
859
                        return nil
×
860
                }
×
861
                klog.Error(err)
×
862
                return err
×
863
        }
864
        vpc = cachedVpc.DeepCopy()
×
865
        // make sure custom policies not be deleted
×
866
        _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Update(context.Background(), vpc, metav1.UpdateOptions{})
×
867
        if err != nil {
×
868
                klog.Error(err)
×
869
                return err
×
870
        }
×
871
        return nil
×
872
}
873

874
func (c *Controller) addStaticRouteToVpc(name string, route *kubeovnv1.StaticRoute) error {
×
875
        if route.BfdID != "" {
×
876
                klog.Infof("vpc %s add static ecmp route: %+v", name, route)
×
877
                if err := c.OVNNbClient.AddLogicalRouterStaticRoute(
×
878
                        name, route.RouteTable, convertPolicy(route.Policy), route.CIDR, &route.BfdID, nil, route.NextHopIP,
×
879
                ); err != nil {
×
880
                        klog.Errorf("failed to add bfd static route to vpc %s , %v", name, err)
×
881
                        return err
×
882
                }
×
883
        } else {
×
884
                klog.Infof("vpc %s add static route: %+v", name, route)
×
885
                if err := c.OVNNbClient.AddLogicalRouterStaticRoute(
×
886
                        name, route.RouteTable, convertPolicy(route.Policy), route.CIDR, nil, nil, route.NextHopIP,
×
887
                ); err != nil {
×
888
                        klog.Errorf("failed to add normal static route to vpc %s , %v", name, err)
×
889
                        return err
×
890
                }
×
891
        }
892
        return nil
×
893
}
894

895
func (c *Controller) deleteStaticRouteFromVpc(name, table, cidr, nextHop string, policy kubeovnv1.RoutePolicy) error {
×
896
        var (
×
897
                policyStr string
×
898
                err       error
×
899
        )
×
900

×
901
        policyStr = convertPolicy(policy)
×
902
        if err = c.OVNNbClient.DeleteLogicalRouterStaticRoute(name, &table, &policyStr, cidr, nextHop); err != nil {
×
903
                klog.Errorf("del vpc %s static route failed, %v", name, err)
×
904
                return err
×
905
        }
×
906

907
        return nil
×
908
}
909

910
func (c *Controller) batchDeleteStaticRouteFromVpc(name string, staticRoutes []*kubeovnv1.StaticRoute) error {
×
911
        var (
×
912
                vpc, cachedVpc *kubeovnv1.Vpc
×
913
                err            error
×
914
        )
×
915
        start := time.Now()
×
916
        routeCount := len(staticRoutes)
×
917
        delRoutes := make([]*ovnnb.LogicalRouterStaticRoute, 0, routeCount)
×
918
        for _, sr := range staticRoutes {
×
919
                policyStr := convertPolicy(sr.Policy)
×
920
                newRoute := &ovnnb.LogicalRouterStaticRoute{
×
921
                        RouteTable: sr.RouteTable,
×
922
                        Nexthop:    sr.NextHopIP,
×
923
                        Policy:     &policyStr,
×
924
                        IPPrefix:   sr.CIDR,
×
925
                }
×
926
                delRoutes = append(delRoutes, newRoute)
×
927
        }
×
928
        if err = c.OVNNbClient.BatchDeleteLogicalRouterStaticRoute(name, delRoutes); err != nil {
×
929
                klog.Errorf("batch del vpc %s static route %d failed, %v", name, routeCount, err)
×
930
                return err
×
931
        }
×
932
        klog.V(3).Infof("take to %v batch delete static route from vpc %s static routes %d", time.Since(start), name, len(delRoutes))
×
933

×
934
        cachedVpc, err = c.vpcsLister.Get(name)
×
935
        if err != nil {
×
936
                if k8serrors.IsNotFound(err) {
×
937
                        return nil
×
938
                }
×
939
                klog.Error(err)
×
940
                return err
×
941
        }
942
        vpc = cachedVpc.DeepCopy()
×
943
        // make sure custom policies not be deleted
×
944
        _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Update(context.Background(), vpc, metav1.UpdateOptions{})
×
945
        if err != nil {
×
946
                klog.Error(err)
×
947
                return err
×
948
        }
×
949
        return nil
×
950
}
951

952
func diffPolicyRouteWithExisted(exists, target []*kubeovnv1.PolicyRoute) ([]*kubeovnv1.PolicyRoute, []*kubeovnv1.PolicyRoute) {
×
953
        var (
×
954
                dels, adds []*kubeovnv1.PolicyRoute
×
955
                existsMap  map[string]*kubeovnv1.PolicyRoute
×
956
                key        string
×
957
                ok         bool
×
958
        )
×
959

×
960
        existsMap = make(map[string]*kubeovnv1.PolicyRoute, len(exists))
×
961
        for _, item := range exists {
×
962
                existsMap[getPolicyRouteItemKey(item)] = item
×
963
        }
×
964
        // load policies to add
965
        for _, item := range target {
×
966
                key = getPolicyRouteItemKey(item)
×
967

×
968
                if _, ok = existsMap[key]; ok {
×
969
                        delete(existsMap, key)
×
970
                } else {
×
971
                        adds = append(adds, item)
×
972
                }
×
973
        }
974
        // load policies to delete
975
        for _, item := range existsMap {
×
976
                dels = append(dels, item)
×
977
        }
×
978
        return dels, adds
×
979
}
980

981
func diffPolicyRouteWithLogical(exists []*ovnnb.LogicalRouterPolicy, target []*kubeovnv1.PolicyRoute) ([]*kubeovnv1.PolicyRoute, []*kubeovnv1.PolicyRoute) {
×
982
        var (
×
983
                dels, adds []*kubeovnv1.PolicyRoute
×
984
                existsMap  map[string]*kubeovnv1.PolicyRoute
×
985
                key        string
×
986
                ok         bool
×
987
        )
×
988
        existsMap = make(map[string]*kubeovnv1.PolicyRoute, len(exists))
×
989

×
990
        for _, item := range exists {
×
991
                policy := &kubeovnv1.PolicyRoute{
×
992
                        Priority: item.Priority,
×
993
                        Match:    item.Match,
×
994
                        Action:   kubeovnv1.PolicyRouteAction(item.Action),
×
995
                }
×
996
                existsMap[getPolicyRouteItemKey(policy)] = policy
×
997
        }
×
998

999
        for _, item := range target {
×
1000
                key = getPolicyRouteItemKey(item)
×
1001

×
1002
                if _, ok = existsMap[key]; ok {
×
1003
                        delete(existsMap, key)
×
1004
                } else {
×
1005
                        adds = append(adds, item)
×
1006
                }
×
1007
        }
1008

1009
        for _, item := range existsMap {
×
1010
                dels = append(dels, item)
×
1011
        }
×
1012
        return dels, adds
×
1013
}
1014

1015
func getPolicyRouteItemKey(item *kubeovnv1.PolicyRoute) (key string) {
×
1016
        return fmt.Sprintf("%d:%s:%s:%s", item.Priority, item.Match, item.Action, item.NextHopIP)
×
1017
}
×
1018

1019
func diffStaticRoute(exist []*ovnnb.LogicalRouterStaticRoute, target []*kubeovnv1.StaticRoute) (routeNeedDel, routeNeedAdd []*kubeovnv1.StaticRoute, err error) {
×
1020
        existRouteMap := make(map[string]*kubeovnv1.StaticRoute, len(exist))
×
1021
        for _, item := range exist {
×
1022
                policy := kubeovnv1.PolicyDst
×
1023
                if item.Policy != nil && *item.Policy == ovnnb.LogicalRouterStaticRoutePolicySrcIP {
×
1024
                        policy = kubeovnv1.PolicySrc
×
1025
                }
×
1026
                route := &kubeovnv1.StaticRoute{
×
1027
                        Policy:     policy,
×
1028
                        CIDR:       item.IPPrefix,
×
1029
                        NextHopIP:  item.Nexthop,
×
1030
                        RouteTable: item.RouteTable,
×
1031
                        ECMPMode:   util.StaticRouteBfdEcmp,
×
1032
                }
×
1033
                if item.BFD != nil {
×
1034
                        route.BfdID = *item.BFD
×
1035
                }
×
1036
                existRouteMap[getStaticRouteItemKey(route)] = route
×
1037
        }
1038

1039
        for _, item := range target {
×
1040
                key := getStaticRouteItemKey(item)
×
1041
                if _, ok := existRouteMap[key]; ok {
×
1042
                        delete(existRouteMap, key)
×
1043
                } else {
×
1044
                        routeNeedAdd = append(routeNeedAdd, item)
×
1045
                }
×
1046
        }
1047
        for _, item := range existRouteMap {
×
1048
                routeNeedDel = append(routeNeedDel, item)
×
1049
        }
×
1050
        return
×
1051
}
1052

1053
func getStaticRouteItemKey(item *kubeovnv1.StaticRoute) string {
×
1054
        var key string
×
1055
        if item.Policy == kubeovnv1.PolicyDst {
×
1056
                key = fmt.Sprintf("%s:dst:%s=>%s", item.RouteTable, item.CIDR, item.NextHopIP)
×
1057
        } else {
×
1058
                key = fmt.Sprintf("%s:src:%s=>%s", item.RouteTable, item.CIDR, item.NextHopIP)
×
1059
        }
×
1060
        return key
×
1061
}
1062

1063
func (c *Controller) formatVpc(vpc *kubeovnv1.Vpc) (*kubeovnv1.Vpc, error) {
×
1064
        var changed bool
×
1065
        for _, item := range vpc.Spec.StaticRoutes {
×
1066
                // check policy
×
1067
                if item.Policy == "" {
×
1068
                        item.Policy = kubeovnv1.PolicyDst
×
1069
                        changed = true
×
1070
                }
×
1071
                if item.Policy != kubeovnv1.PolicyDst && item.Policy != kubeovnv1.PolicySrc {
×
1072
                        return nil, fmt.Errorf("unknown policy type: %q", item.Policy)
×
1073
                }
×
1074
                // check cidr
1075
                if strings.Contains(item.CIDR, "/") {
×
1076
                        if _, _, err := net.ParseCIDR(item.CIDR); err != nil {
×
1077
                                return nil, fmt.Errorf("invalid cidr %q: %w", item.CIDR, err)
×
1078
                        }
×
1079
                } else if ip := net.ParseIP(item.CIDR); ip == nil {
×
1080
                        return nil, fmt.Errorf("invalid ip %q", item.CIDR)
×
1081
                }
×
1082
                // check next hop ip
1083
                if ip := net.ParseIP(item.NextHopIP); ip == nil {
×
1084
                        return nil, fmt.Errorf("invalid next hop ip %q", item.NextHopIP)
×
1085
                }
×
1086
        }
1087

1088
        for _, route := range vpc.Spec.PolicyRoutes {
×
1089
                if route.Action != kubeovnv1.PolicyRouteActionReroute {
×
1090
                        if route.NextHopIP != "" {
×
1091
                                route.NextHopIP = ""
×
1092
                                changed = true
×
1093
                        }
×
1094
                } else {
×
1095
                        // ecmp policy route may reroute to multiple next hop ips
×
1096
                        for _, ipStr := range strings.Split(route.NextHopIP, ",") {
×
1097
                                if ip := net.ParseIP(ipStr); ip == nil {
×
1098
                                        err := fmt.Errorf("invalid next hop ips: %s", route.NextHopIP)
×
1099
                                        klog.Error(err)
×
1100
                                        return nil, err
×
1101
                                }
×
1102
                        }
1103
                }
1104
        }
1105

NEW
1106
        if vpc.DeletionTimestamp.IsZero() && !slices.Contains(vpc.GetFinalizers(), util.KubeOVNControllerFinalizer) {
×
NEW
1107
                controllerutil.AddFinalizer(vpc, util.KubeOVNControllerFinalizer)
×
NEW
1108
                changed = true
×
NEW
1109
        }
×
1110

NEW
1111
        if !vpc.DeletionTimestamp.IsZero() && len(vpc.Status.Subnets) == 0 {
×
NEW
1112
                controllerutil.RemoveFinalizer(vpc, util.KubeOVNControllerFinalizer)
×
NEW
1113
                changed = true
×
NEW
1114
        }
×
1115

1116
        if changed {
×
1117
                newVpc, err := c.config.KubeOvnClient.KubeovnV1().Vpcs().Update(context.Background(), vpc, metav1.UpdateOptions{})
×
1118
                if err != nil {
×
1119
                        klog.Errorf("failed to update vpc %s: %v", vpc.Name, err)
×
1120
                        return nil, err
×
1121
                }
×
1122
                return newVpc, nil
×
1123
        }
1124

1125
        return vpc, nil
×
1126
}
1127

1128
func convertPolicies(list []*kubeovnv1.PolicyRoute) string {
×
1129
        if list == nil {
×
1130
                return ""
×
1131
        }
×
1132

1133
        var (
×
1134
                res []byte
×
1135
                err error
×
1136
        )
×
1137

×
1138
        if res, err = json.Marshal(list); err != nil {
×
1139
                klog.Errorf("failed to serialize policy routes %v , reason : %v", list, err)
×
1140
                return ""
×
1141
        }
×
1142
        return string(res)
×
1143
}
1144

1145
func reversePolicies(origin string) []*kubeovnv1.PolicyRoute {
×
1146
        if origin == "" {
×
1147
                return nil
×
1148
        }
×
1149

1150
        var (
×
1151
                list []*kubeovnv1.PolicyRoute
×
1152
                err  error
×
1153
        )
×
1154

×
1155
        if err = json.Unmarshal([]byte(origin), &list); err != nil {
×
1156
                klog.Errorf("failed to deserialize policy routes %v , reason : %v", list, err)
×
1157
                return nil
×
1158
        }
×
1159
        return list
×
1160
}
1161

1162
func convertPolicy(origin kubeovnv1.RoutePolicy) string {
×
1163
        if origin == kubeovnv1.PolicyDst {
×
1164
                return ovnnb.LogicalRouterStaticRoutePolicyDstIP
×
1165
        }
×
1166
        return ovnnb.LogicalRouterStaticRoutePolicySrcIP
×
1167
}
1168

1169
func reversePolicy(origin ovnnb.LogicalRouterStaticRoutePolicy) kubeovnv1.RoutePolicy {
×
1170
        if origin == ovnnb.LogicalRouterStaticRoutePolicyDstIP {
×
1171
                return kubeovnv1.PolicyDst
×
1172
        }
×
1173
        return kubeovnv1.PolicySrc
×
1174
}
1175

1176
func (c *Controller) getVpcSubnets(vpc *kubeovnv1.Vpc) (subnets []string, defaultSubnet string, err error) {
×
1177
        subnets = []string{}
×
1178
        allSubnets, err := c.subnetsLister.List(labels.Everything())
×
1179
        if err != nil {
×
1180
                klog.Error(err)
×
1181
                return nil, "", err
×
1182
        }
×
1183

1184
        for _, subnet := range allSubnets {
×
1185
                if subnet.Spec.Vpc != vpc.Name || !subnet.DeletionTimestamp.IsZero() || !isOvnSubnet(subnet) {
×
1186
                        continue
×
1187
                }
1188

1189
                subnets = append(subnets, subnet.Name)
×
1190
                if subnet.Spec.Default {
×
1191
                        defaultSubnet = subnet.Name
×
1192
                }
×
1193

1194
                if vpc.Name != util.DefaultVpc && vpc.Spec.DefaultSubnet != "" && vpc.Spec.DefaultSubnet == subnet.Name {
×
1195
                        defaultSubnet = vpc.Spec.DefaultSubnet
×
1196
                }
×
1197
        }
1198
        return
×
1199
}
1200

1201
// createVpcRouter create router to connect logical switches in vpc
1202
func (c *Controller) createVpcRouter(lr string) error {
×
1203
        if err := c.OVNNbClient.CreateLogicalRouter(lr); err != nil {
×
1204
                klog.Errorf("create logical router %s failed: %v", lr, err)
×
1205
                return err
×
1206
        }
×
1207

1208
        vpcRouter, err := c.OVNNbClient.GetLogicalRouter(lr, false)
×
1209
        if err != nil {
×
1210
                klog.Errorf("get logical router %s failed: %v", lr, err)
×
1211
                return err
×
1212
        }
×
1213

1214
        vpcRouter.Options = map[string]string{"always_learn_from_arp_request": "false", "dynamic_neigh_routers": "true", "mac_binding_age_threshold": "300"}
×
1215
        err = c.OVNNbClient.UpdateLogicalRouter(vpcRouter, &vpcRouter.Options)
×
1216
        if err != nil {
×
1217
                klog.Errorf("update logical router %s failed: %v", lr, err)
×
1218
                return err
×
1219
        }
×
1220
        return nil
×
1221
}
1222

1223
// deleteVpcRouter delete router to connect logical switches in vpc
1224
func (c *Controller) deleteVpcRouter(lr string) error {
×
1225
        return c.OVNNbClient.DeleteLogicalRouter(lr)
×
1226
}
×
1227

1228
func (c *Controller) handleAddVpcExternalSubnet(key, subnet string) error {
×
1229
        cachedSubnet, err := c.subnetsLister.Get(subnet)
×
1230
        if err != nil {
×
1231
                klog.Error(err)
×
1232
                return err
×
1233
        }
×
1234
        lrpEipName := fmt.Sprintf("%s-%s", key, subnet)
×
1235
        cachedEip, err := c.ovnEipsLister.Get(lrpEipName)
×
1236
        var needCreateEip bool
×
1237
        if err != nil {
×
1238
                if !k8serrors.IsNotFound(err) {
×
1239
                        klog.Error(err)
×
1240
                        return err
×
1241
                }
×
1242
                needCreateEip = true
×
1243
        }
1244
        var v4ip, v6ip, mac string
×
1245
        klog.V(3).Infof("create vpc lrp eip %s", lrpEipName)
×
1246
        if needCreateEip {
×
1247
                if v4ip, v6ip, mac, err = c.acquireIPAddress(subnet, lrpEipName, lrpEipName); err != nil {
×
1248
                        klog.Errorf("failed to acquire ip address for lrp eip %s, %v", lrpEipName, err)
×
1249
                        return err
×
1250
                }
×
1251
                if err := c.createOrUpdateOvnEipCR(lrpEipName, subnet, v4ip, v6ip, mac, util.OvnEipTypeLRP); err != nil {
×
1252
                        klog.Errorf("failed to create ovn eip for lrp %s: %v", lrpEipName, err)
×
1253
                        return err
×
1254
                }
×
1255
        } else {
×
1256
                v4ip = cachedEip.Spec.V4Ip
×
1257
                mac = cachedEip.Spec.MacAddress
×
1258
        }
×
1259
        if v4ip == "" || mac == "" {
×
1260
                err := fmt.Errorf("lrp '%s' ip or mac should not be empty", lrpEipName)
×
1261
                klog.Error(err)
×
1262
                return err
×
1263
        }
×
1264
        // init lrp gw chassis group
1265
        chassises := []string{}
×
1266
        sel, _ := metav1.LabelSelectorAsSelector(&metav1.LabelSelector{MatchLabels: map[string]string{util.ExGatewayLabel: "true"}})
×
1267
        gwNodes, err := c.nodesLister.List(sel)
×
1268
        if err != nil {
×
1269
                klog.Errorf("failed to list external gw nodes, %v", err)
×
1270
                return err
×
1271
        }
×
1272
        for _, gwNode := range gwNodes {
×
1273
                annoChassisName := gwNode.Annotations[util.ChassisAnnotation]
×
1274
                if annoChassisName == "" {
×
1275
                        err := fmt.Errorf("node %s has no chassis annotation, kube-ovn-cni not ready", gwNode.Name)
×
1276
                        klog.Error(err)
×
1277
                        return err
×
1278
                }
×
1279
                klog.Infof("get node %s chassis: %s", gwNode.Name, annoChassisName)
×
1280
                chassis, err := c.OVNSbClient.GetChassis(annoChassisName, false)
×
1281
                if err != nil {
×
1282
                        klog.Errorf("failed to get node %s chassis: %s, %v", gwNode.Name, annoChassisName, err)
×
1283
                        return err
×
1284
                }
×
1285
                chassises = append(chassises, chassis.Name)
×
1286
        }
1287

1288
        if len(chassises) == 0 {
×
1289
                err := errors.New("no external gw nodes")
×
1290
                klog.Error(err)
×
1291
                return err
×
1292
        }
×
1293

1294
        v4ipCidr, err := util.GetIPAddrWithMask(v4ip, cachedSubnet.Spec.CIDRBlock)
×
1295
        if err != nil {
×
1296
                klog.Error(err)
×
1297
                return err
×
1298
        }
×
1299
        lspName := fmt.Sprintf("%s-%s", subnet, key)
×
1300
        lrpName := fmt.Sprintf("%s-%s", key, subnet)
×
1301

×
1302
        if err := c.OVNNbClient.CreateLogicalPatchPort(subnet, key, lspName, lrpName, v4ipCidr, mac, chassises...); err != nil {
×
1303
                klog.Errorf("failed to connect router '%s' to external: %v", key, err)
×
1304
                return err
×
1305
        }
×
1306

1307
        cachedVpc, err := c.vpcsLister.Get(key)
×
1308
        if err != nil {
×
1309
                if k8serrors.IsNotFound(err) {
×
1310
                        return nil
×
1311
                }
×
1312
                klog.Errorf("failed to get vpc %s, %v", key, err)
×
1313
                return err
×
1314
        }
1315
        if subnet == c.config.ExternalGatewaySwitch {
×
1316
                vpc := cachedVpc.DeepCopy()
×
1317
                vpc.Status.EnableExternal = cachedVpc.Spec.EnableExternal
×
1318
                bytes, err := vpc.Status.Bytes()
×
1319
                if err != nil {
×
1320
                        klog.Errorf("failed to marshal vpc status: %v", err)
×
1321
                        return err
×
1322
                }
×
1323
                if _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Patch(context.Background(),
×
1324
                        vpc.Name, types.MergePatchType, bytes, metav1.PatchOptions{}, "status"); err != nil {
×
1325
                        err := fmt.Errorf("failed to patch vpc %s status, %w", vpc.Name, err)
×
1326
                        klog.Error(err)
×
1327
                        return err
×
1328
                }
×
1329
        }
1330
        if _, err = c.ovnEipsLister.Get(lrpEipName); err != nil {
×
1331
                err := fmt.Errorf("failed to get ovn eip %s, %w", lrpEipName, err)
×
1332
                klog.Error(err)
×
1333
                return err
×
1334
        }
×
1335
        return nil
×
1336
}
1337

1338
func (c *Controller) handleDeleteVpcStaticRoute(key string) error {
×
1339
        vpc, err := c.vpcsLister.Get(key)
×
1340
        if err != nil {
×
1341
                if k8serrors.IsNotFound(err) {
×
1342
                        return nil
×
1343
                }
×
1344
                klog.Errorf("failed to get vpc %s, %v", key, err)
×
1345
                return err
×
1346
        }
1347
        needUpdate := false
×
1348
        newStaticRoutes := make([]*kubeovnv1.StaticRoute, 0, len(vpc.Spec.StaticRoutes))
×
1349
        for _, route := range vpc.Spec.StaticRoutes {
×
1350
                if route.ECMPMode != util.StaticRouteBfdEcmp {
×
1351
                        newStaticRoutes = append(newStaticRoutes, route)
×
1352
                        needUpdate = true
×
1353
                }
×
1354
        }
1355
        // keep non ecmp bfd routes
1356
        vpc.Spec.StaticRoutes = newStaticRoutes
×
1357
        if needUpdate {
×
1358
                if _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Update(context.Background(), vpc, metav1.UpdateOptions{}); err != nil {
×
1359
                        klog.Errorf("failed to update vpc spec static route %s, %v", vpc.Name, err)
×
1360
                        return err
×
1361
                }
×
1362
        }
1363
        if err = c.patchVpcBfdStatus(vpc.Name); err != nil {
×
1364
                klog.Errorf("failed to patch vpc %s, %v", vpc.Name, err)
×
1365
                return err
×
1366
        }
×
1367
        return nil
×
1368
}
1369

1370
func (c *Controller) handleDelVpcExternalSubnet(key, subnet string) error {
×
1371
        lspName := fmt.Sprintf("%s-%s", subnet, key)
×
1372
        lrpName := fmt.Sprintf("%s-%s", key, subnet)
×
1373
        klog.V(3).Infof("delete vpc lrp %s", lrpName)
×
1374
        if err := c.OVNNbClient.RemoveLogicalPatchPort(lspName, lrpName); err != nil {
×
1375
                klog.Errorf("failed to disconnect router '%s' to external, %v", key, err)
×
1376
                return err
×
1377
        }
×
1378

1379
        if err := c.config.KubeOvnClient.KubeovnV1().OvnEips().Delete(context.Background(), lrpName, metav1.DeleteOptions{}); err != nil {
×
1380
                if !k8serrors.IsNotFound(err) {
×
1381
                        klog.Errorf("failed to delete ovn eip %s, %v", lrpName, err)
×
1382
                        return err
×
1383
                }
×
1384
        }
1385
        if err := c.OVNNbClient.DeleteBFDByDstIP(lrpName, ""); err != nil {
×
1386
                klog.Error(err)
×
1387
                return err
×
1388
        }
×
1389
        cachedVpc, err := c.vpcsLister.Get(key)
×
1390
        if err != nil {
×
1391
                if k8serrors.IsNotFound(err) {
×
1392
                        return nil
×
1393
                }
×
1394
                klog.Errorf("failed to get vpc %s, %v", key, err)
×
1395
                return err
×
1396
        }
1397
        if subnet == c.config.ExternalGatewaySwitch {
×
1398
                vpc := cachedVpc.DeepCopy()
×
1399
                vpc.Status.EnableExternal = cachedVpc.Spec.EnableExternal
×
1400
                vpc.Status.EnableBfd = cachedVpc.Spec.EnableBfd
×
1401
                bytes, err := vpc.Status.Bytes()
×
1402
                if err != nil {
×
1403
                        klog.Errorf("failed to marshal vpc status: %v", err)
×
1404
                        return err
×
1405
                }
×
1406
                if _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Patch(context.Background(),
×
1407
                        vpc.Name, types.MergePatchType, bytes, metav1.PatchOptions{}, "status"); err != nil {
×
1408
                        if k8serrors.IsNotFound(err) {
×
1409
                                return nil
×
1410
                        }
×
1411
                        klog.Errorf("failed to patch vpc %s, %v", key, err)
×
1412
                        return err
×
1413
                }
1414
        }
1415
        return nil
×
1416
}
1417

1418
func (c *Controller) patchVpcBfdStatus(key string) error {
×
1419
        cachedVpc, err := c.vpcsLister.Get(key)
×
1420
        if err != nil {
×
1421
                if k8serrors.IsNotFound(err) {
×
1422
                        return nil
×
1423
                }
×
1424
                klog.Errorf("failed to get vpc %s, %v", key, err)
×
1425
                return err
×
1426
        }
1427

1428
        if cachedVpc.Status.EnableBfd != cachedVpc.Spec.EnableBfd {
×
1429
                status := cachedVpc.Status.DeepCopy()
×
1430
                status.EnableExternal = cachedVpc.Spec.EnableExternal
×
1431
                status.EnableBfd = cachedVpc.Spec.EnableBfd
×
1432
                bytes, err := status.Bytes()
×
1433
                if err != nil {
×
1434
                        klog.Errorf("failed to marshal vpc status: %v", err)
×
1435
                        return err
×
1436
                }
×
1437
                if _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Patch(context.Background(),
×
1438
                        cachedVpc.Name, types.MergePatchType, bytes, metav1.PatchOptions{}, "status"); err != nil {
×
1439
                        klog.Error(err)
×
1440
                        return err
×
1441
                }
×
1442
        }
1443
        return nil
×
1444
}
1445

1446
func (c *Controller) getRouteTablesByVpc(vpc *kubeovnv1.Vpc) map[string][]*kubeovnv1.StaticRoute {
×
1447
        rtbs := make(map[string][]*kubeovnv1.StaticRoute)
×
1448
        for _, route := range vpc.Spec.StaticRoutes {
×
1449
                rtbs[route.RouteTable] = append(rtbs[route.RouteTable], route)
×
1450
        }
×
1451
        return rtbs
×
1452
}
1453

1454
func (c *Controller) updateVpcAddExternalStatus(key string, addExternalStatus bool) error {
×
1455
        cachedVpc, err := c.vpcsLister.Get(key)
×
1456
        if err != nil {
×
1457
                klog.Errorf("failed to get vpc %s, %v", key, err)
×
1458
                return err
×
1459
        }
×
1460
        vpc := cachedVpc.DeepCopy()
×
1461
        if addExternalStatus && vpc.Spec.ExtraExternalSubnets != nil {
×
1462
                sort.Strings(vpc.Spec.ExtraExternalSubnets)
×
1463
                vpc.Status.ExtraExternalSubnets = vpc.Spec.ExtraExternalSubnets
×
1464
        } else {
×
1465
                vpc.Status.ExtraExternalSubnets = nil
×
1466
        }
×
1467
        bytes, err := vpc.Status.Bytes()
×
1468
        if err != nil {
×
1469
                klog.Errorf("failed to get vpc bytes, %v", err)
×
1470
                return err
×
1471
        }
×
1472
        if _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Patch(context.Background(),
×
1473
                vpc.Name, types.MergePatchType, bytes, metav1.PatchOptions{}, "status"); err != nil {
×
1474
                klog.Errorf("failed to patch vpc %s, %v", key, err)
×
1475
                return err
×
1476
        }
×
1477

1478
        return nil
×
1479
}
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc