• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

kubeovn / kube-ovn / 15269660763

27 May 2025 07:51AM UTC coverage: 21.822%. First build
15269660763

Pull #5268

github

web-flow
Merge branch 'master' into vpc-any-external
Pull Request #5268: any vpc can use any external subnet

0 of 131 new or added lines in 2 files covered. (0.0%)

10363 of 47488 relevant lines covered (21.82%)

0.25 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

0.0
/pkg/controller/vpc.go
1
package controller
2

3
import (
4
        "context"
5
        "encoding/json"
6
        "errors"
7
        "fmt"
8
        "maps"
9
        "math"
10
        "net"
11
        "reflect"
12
        "slices"
13
        "sort"
14
        "strings"
15
        "time"
16

17
        v1 "k8s.io/api/core/v1"
18
        k8serrors "k8s.io/apimachinery/pkg/api/errors"
19
        metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
20
        "k8s.io/apimachinery/pkg/labels"
21
        "k8s.io/apimachinery/pkg/types"
22
        "k8s.io/client-go/tools/cache"
23
        "k8s.io/klog/v2"
24
        "sigs.k8s.io/controller-runtime/pkg/controller/controllerutil"
25

26
        kubeovnv1 "github.com/kubeovn/kube-ovn/pkg/apis/kubeovn/v1"
27
        "github.com/kubeovn/kube-ovn/pkg/ovsdb/ovnnb"
28
        "github.com/kubeovn/kube-ovn/pkg/util"
29
)
30

31
func (c *Controller) enqueueAddVpc(obj any) {
×
32
        vpc := obj.(*kubeovnv1.Vpc)
×
33
        key := cache.MetaObjectToName(vpc).String()
×
34
        if _, ok := vpc.Labels[util.VpcExternalLabel]; !ok {
×
35
                klog.V(3).Infof("enqueue add vpc %s", key)
×
36
                c.addOrUpdateVpcQueue.Add(key)
×
37
        }
×
38
}
39

40
func vpcBFDPortChanged(oldObj, newObj *kubeovnv1.BFDPort) bool {
×
41
        if oldObj == nil && newObj == nil {
×
42
                return false
×
43
        }
×
44
        if oldObj == nil || newObj == nil {
×
45
                return true
×
46
        }
×
47
        return oldObj.Enabled != newObj.Enabled || oldObj.IP != newObj.IP || !reflect.DeepEqual(oldObj.NodeSelector, newObj.NodeSelector)
×
48
}
49

50
func (c *Controller) enqueueUpdateVpc(oldObj, newObj any) {
×
51
        oldVpc := oldObj.(*kubeovnv1.Vpc)
×
52
        newVpc := newObj.(*kubeovnv1.Vpc)
×
53

×
54
        if !newVpc.DeletionTimestamp.IsZero() ||
×
55
                !slices.Equal(oldVpc.Spec.Namespaces, newVpc.Spec.Namespaces) ||
×
56
                !reflect.DeepEqual(oldVpc.Spec.StaticRoutes, newVpc.Spec.StaticRoutes) ||
×
57
                !reflect.DeepEqual(oldVpc.Spec.PolicyRoutes, newVpc.Spec.PolicyRoutes) ||
×
58
                !reflect.DeepEqual(oldVpc.Spec.VpcPeerings, newVpc.Spec.VpcPeerings) ||
×
59
                !maps.Equal(oldVpc.Annotations, newVpc.Annotations) ||
×
60
                !slices.Equal(oldVpc.Spec.ExtraExternalSubnets, newVpc.Spec.ExtraExternalSubnets) ||
×
61
                oldVpc.Spec.EnableExternal != newVpc.Spec.EnableExternal ||
×
62
                oldVpc.Spec.EnableBfd != newVpc.Spec.EnableBfd ||
×
63
                vpcBFDPortChanged(oldVpc.Spec.BFDPort, newVpc.Spec.BFDPort) ||
×
64
                oldVpc.Labels[util.VpcExternalLabel] != newVpc.Labels[util.VpcExternalLabel] {
×
65
                // TODO:// label VpcExternalLabel replace with spec enable external
×
66

×
67
                if newVpc.Annotations == nil {
×
68
                        newVpc.Annotations = make(map[string]string)
×
69
                }
×
70
                newVpc.Annotations[util.VpcLastPolicies] = convertPolicies(oldVpc.Spec.PolicyRoutes)
×
71

×
72
                key := cache.MetaObjectToName(newVpc).String()
×
73
                klog.Infof("enqueue update vpc %s", key)
×
74
                c.addOrUpdateVpcQueue.Add(key)
×
75
        }
76
}
77

78
func (c *Controller) enqueueDelVpc(obj any) {
×
79
        vpc := obj.(*kubeovnv1.Vpc)
×
80
        if _, ok := vpc.Labels[util.VpcExternalLabel]; !vpc.Status.Default || !ok {
×
81
                klog.V(3).Infof("enqueue delete vpc %s", vpc.Name)
×
82
                c.delVpcQueue.Add(vpc)
×
83
        }
×
84
}
85

86
func (c *Controller) handleDelVpc(vpc *kubeovnv1.Vpc) error {
×
87
        c.vpcKeyMutex.LockKey(vpc.Name)
×
88
        defer func() { _ = c.vpcKeyMutex.UnlockKey(vpc.Name) }()
×
89
        klog.Infof("handle delete vpc %s", vpc.Name)
×
90

×
91
        // should delete vpc subnets first
×
92
        var err error
×
93
        for _, subnet := range vpc.Status.Subnets {
×
94
                if _, err = c.subnetsLister.Get(subnet); err != nil {
×
95
                        if k8serrors.IsNotFound(err) {
×
96
                                continue
×
97
                        }
98
                        err = fmt.Errorf("failed to get subnet %s for vpc %s: %w", subnet, vpc.Name, err)
×
99
                } else {
×
100
                        err = fmt.Errorf("failed to delete vpc %s, please delete subnet %s first", vpc.Name, subnet)
×
101
                }
×
102
                klog.Error(err)
×
103
                return err
×
104
        }
105

106
        if err := c.deleteVpcLb(vpc); err != nil {
×
107
                klog.Error(err)
×
108
                return err
×
109
        }
×
110

111
        if err := c.handleDelVpcExternalSubnet(vpc.Name, c.config.ExternalGatewaySwitch); err != nil {
×
112
                klog.Errorf("failed to delete external connection for vpc %s, error %v", vpc.Name, err)
×
113
                return err
×
114
        }
×
115

116
        for _, subnet := range vpc.Status.ExtraExternalSubnets {
×
117
                klog.Infof("disconnect external network %s to vpc %s", subnet, vpc.Name)
×
118
                if err := c.handleDelVpcExternalSubnet(vpc.Name, subnet); err != nil {
×
119
                        klog.Error(err)
×
120
                        return err
×
121
                }
×
122
        }
123

124
        if err := c.deleteVpcRouter(vpc.Status.Router); err != nil {
×
125
                klog.Error(err)
×
126
                return err
×
127
        }
×
128

129
        return nil
×
130
}
131

132
func (c *Controller) handleUpdateVpcStatus(key string) error {
×
133
        c.vpcKeyMutex.LockKey(key)
×
134
        defer func() { _ = c.vpcKeyMutex.UnlockKey(key) }()
×
135
        klog.Infof("handle status update for vpc %s", key)
×
136

×
137
        cachedVpc, err := c.vpcsLister.Get(key)
×
138
        if err != nil {
×
139
                if k8serrors.IsNotFound(err) {
×
140
                        return nil
×
141
                }
×
142
                klog.Error(err)
×
143
                return err
×
144
        }
145
        vpc := cachedVpc.DeepCopy()
×
146

×
147
        subnets, defaultSubnet, err := c.getVpcSubnets(vpc)
×
148
        if err != nil {
×
149
                klog.Error(err)
×
150
                return err
×
151
        }
×
152

153
        change := vpc.Status.DefaultLogicalSwitch != defaultSubnet
×
154

×
155
        vpc.Status.DefaultLogicalSwitch = defaultSubnet
×
156
        vpc.Status.Subnets = subnets
×
157

×
158
        if !vpc.Spec.BFDPort.IsEnabled() && !vpc.Status.BFDPort.IsEmpty() {
×
159
                vpc.Status.BFDPort.Clear()
×
160
        }
×
161
        bytes, err := vpc.Status.Bytes()
×
162
        if err != nil {
×
163
                klog.Error(err)
×
164
                return err
×
165
        }
×
166

167
        vpc, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Patch(context.Background(), vpc.Name, types.MergePatchType, bytes, metav1.PatchOptions{}, "status")
×
168
        if err != nil {
×
169
                klog.Error(err)
×
170
                return err
×
171
        }
×
172

173
        if len(vpc.Status.Subnets) == 0 {
×
174
                klog.Infof("vpc %s has no subnets, add to queue", vpc.Name)
×
175
                c.addOrUpdateVpcQueue.AddAfter(vpc.Name, 5*time.Second)
×
176
        }
×
177

178
        if change {
×
179
                for _, ns := range vpc.Spec.Namespaces {
×
180
                        c.addNamespaceQueue.Add(ns)
×
181
                }
×
182
        }
183

184
        natGws, err := c.vpcNatGatewayLister.List(labels.Everything())
×
185
        if err != nil {
×
186
                klog.Error(err)
×
187
                return err
×
188
        }
×
189
        for _, gw := range natGws {
×
190
                if key == gw.Spec.Vpc {
×
191
                        c.updateVpcSubnetQueue.Add(gw.Name)
×
192
                }
×
193
        }
194
        return nil
×
195
}
196

197
type VpcLoadBalancer struct {
198
        TCPLoadBalancer      string
199
        TCPSessLoadBalancer  string
200
        UDPLoadBalancer      string
201
        UDPSessLoadBalancer  string
202
        SctpLoadBalancer     string
203
        SctpSessLoadBalancer string
204
}
205

206
func (c *Controller) GenVpcLoadBalancer(vpcKey string) *VpcLoadBalancer {
×
207
        if vpcKey == c.config.ClusterRouter || vpcKey == "" {
×
208
                return &VpcLoadBalancer{
×
209
                        TCPLoadBalancer:      c.config.ClusterTCPLoadBalancer,
×
210
                        TCPSessLoadBalancer:  c.config.ClusterTCPSessionLoadBalancer,
×
211
                        UDPLoadBalancer:      c.config.ClusterUDPLoadBalancer,
×
212
                        UDPSessLoadBalancer:  c.config.ClusterUDPSessionLoadBalancer,
×
213
                        SctpLoadBalancer:     c.config.ClusterSctpLoadBalancer,
×
214
                        SctpSessLoadBalancer: c.config.ClusterSctpSessionLoadBalancer,
×
215
                }
×
216
        }
×
217
        return &VpcLoadBalancer{
×
218
                TCPLoadBalancer:      fmt.Sprintf("vpc-%s-tcp-load", vpcKey),
×
219
                TCPSessLoadBalancer:  fmt.Sprintf("vpc-%s-tcp-sess-load", vpcKey),
×
220
                UDPLoadBalancer:      fmt.Sprintf("vpc-%s-udp-load", vpcKey),
×
221
                UDPSessLoadBalancer:  fmt.Sprintf("vpc-%s-udp-sess-load", vpcKey),
×
222
                SctpLoadBalancer:     fmt.Sprintf("vpc-%s-sctp-load", vpcKey),
×
223
                SctpSessLoadBalancer: fmt.Sprintf("vpc-%s-sctp-sess-load", vpcKey),
×
224
        }
×
225
}
226

227
func (c *Controller) addLoadBalancer(vpc string) (*VpcLoadBalancer, error) {
×
228
        vpcLbConfig := c.GenVpcLoadBalancer(vpc)
×
229
        if err := c.initLB(vpcLbConfig.TCPLoadBalancer, string(v1.ProtocolTCP), false); err != nil {
×
230
                return nil, err
×
231
        }
×
232
        if err := c.initLB(vpcLbConfig.TCPSessLoadBalancer, string(v1.ProtocolTCP), true); err != nil {
×
233
                return nil, err
×
234
        }
×
235
        if err := c.initLB(vpcLbConfig.UDPLoadBalancer, string(v1.ProtocolUDP), false); err != nil {
×
236
                return nil, err
×
237
        }
×
238
        if err := c.initLB(vpcLbConfig.UDPSessLoadBalancer, string(v1.ProtocolUDP), true); err != nil {
×
239
                return nil, err
×
240
        }
×
241
        if err := c.initLB(vpcLbConfig.SctpLoadBalancer, string(v1.ProtocolSCTP), false); err != nil {
×
242
                return nil, err
×
243
        }
×
244
        if err := c.initLB(vpcLbConfig.SctpSessLoadBalancer, string(v1.ProtocolSCTP), true); err != nil {
×
245
                return nil, err
×
246
        }
×
247

248
        return vpcLbConfig, nil
×
249
}
250

251
func (c *Controller) handleAddOrUpdateVpc(key string) error {
×
252
        c.vpcKeyMutex.LockKey(key)
×
253
        defer func() { _ = c.vpcKeyMutex.UnlockKey(key) }()
×
254
        klog.Infof("handle add/update vpc %s", key)
×
255

×
256
        cachedVpc, err := c.vpcsLister.Get(key)
×
257
        if err != nil {
×
258
                if k8serrors.IsNotFound(err) {
×
259
                        return nil
×
260
                }
×
261
                klog.Error(err)
×
262
                return err
×
263
        }
264

265
        vpc, err := c.formatVpc(cachedVpc.DeepCopy())
×
266
        if err != nil {
×
267
                klog.Errorf("failed to format vpc %s: %v", key, err)
×
268
                return err
×
269
        }
×
270

271
        if err = c.createVpcRouter(key); err != nil {
×
272
                klog.Errorf("failed to create vpc router for vpc %s: %v", key, err)
×
273
                return err
×
274
        }
×
275

276
        var newPeers []string
×
277
        for _, peering := range vpc.Spec.VpcPeerings {
×
278
                if err = util.CheckCidrs(peering.LocalConnectIP); err != nil {
×
279
                        klog.Errorf("invalid cidr %s", peering.LocalConnectIP)
×
280
                        return err
×
281
                }
×
282

283
                newPeers = append(newPeers, peering.RemoteVpc)
×
284
                if err := c.OVNNbClient.CreatePeerRouterPort(vpc.Name, peering.RemoteVpc, peering.LocalConnectIP); err != nil {
×
285
                        klog.Errorf("create peer router port for vpc %s, %v", vpc.Name, err)
×
286
                        return err
×
287
                }
×
288
        }
289
        for _, oldPeer := range vpc.Status.VpcPeerings {
×
290
                if !slices.Contains(newPeers, oldPeer) {
×
291
                        if err = c.OVNNbClient.DeleteLogicalRouterPort(fmt.Sprintf("%s-%s", vpc.Name, oldPeer)); err != nil {
×
292
                                klog.Errorf("delete peer router port for vpc %s, %v", vpc.Name, err)
×
293
                                return err
×
294
                        }
×
295
                }
296
        }
297

298
        // handle static route
299
        var (
×
300
                staticExistedRoutes []*ovnnb.LogicalRouterStaticRoute
×
301
                staticTargetRoutes  []*kubeovnv1.StaticRoute
×
302
                staticRouteMapping  map[string][]*kubeovnv1.StaticRoute
×
303
        )
×
304

×
305
        staticExistedRoutes, err = c.OVNNbClient.ListLogicalRouterStaticRoutes(vpc.Name, nil, nil, "", nil)
×
306
        if err != nil {
×
307
                klog.Errorf("failed to get vpc %s static route list, %v", vpc.Name, err)
×
308
                return err
×
309
        }
×
310

311
        var externalSubnet *kubeovnv1.Subnet
×
312
        externalSubnetExist := false
×
NEW
313
        externalSubnetGW := ""
×
314
        if c.config.EnableEipSnat {
×
315
                externalSubnet, err = c.subnetsLister.Get(c.config.ExternalGatewaySwitch)
×
316
                if err != nil {
×
317
                        klog.Warningf("enable-eip-snat need external subnet %s to be exist: %v", c.config.ExternalGatewaySwitch, err)
×
318
                } else {
×
NEW
319
                        if !externalSubnet.Spec.LogicalGateway {
×
NEW
320
                                // logical gw external subnet can not access external
×
NEW
321
                                externalSubnetExist = true
×
NEW
322
                                externalSubnetGW = externalSubnet.Spec.Gateway
×
NEW
323
                        } else {
×
NEW
324
                                klog.Infof("default external subnet %s using logical gw", c.config.ExternalGatewaySwitch)
×
NEW
325
                        }
×
326
                }
327
        }
328

329
        staticRouteMapping = c.getRouteTablesByVpc(vpc)
×
330
        staticTargetRoutes = vpc.Spec.StaticRoutes
×
331
        if vpc.Name == c.config.ClusterRouter {
×
332
                if _, ok := staticRouteMapping[util.MainRouteTable]; !ok {
×
333
                        staticRouteMapping[util.MainRouteTable] = nil
×
334
                }
×
335

336
                joinSubnet, err := c.subnetsLister.Get(c.config.NodeSwitch)
×
337
                if err != nil {
×
338
                        if !k8serrors.IsNotFound(err) {
×
339
                                klog.Errorf("failed to get node switch subnet %s: %v", c.config.NodeSwitch, err)
×
340
                                return err
×
341
                        }
×
342
                        c.addOrUpdateVpcQueue.Add(vpc.Name)
×
343
                        return nil
×
344
                }
345
                gatewayV4, gatewayV6 := util.SplitStringIP(joinSubnet.Spec.Gateway)
×
346
                if gatewayV4 != "" {
×
347
                        for table := range staticRouteMapping {
×
348
                                staticTargetRoutes = append(
×
349
                                        staticTargetRoutes,
×
350
                                        &kubeovnv1.StaticRoute{
×
351
                                                Policy:     kubeovnv1.PolicyDst,
×
352
                                                CIDR:       "0.0.0.0/0",
×
353
                                                NextHopIP:  gatewayV4,
×
354
                                                RouteTable: table,
×
355
                                        },
×
356
                                )
×
357
                        }
×
358
                }
359
                if gatewayV6 != "" {
×
360
                        for table := range staticRouteMapping {
×
361
                                staticTargetRoutes = append(
×
362
                                        staticTargetRoutes,
×
363
                                        &kubeovnv1.StaticRoute{
×
364
                                                Policy:     kubeovnv1.PolicyDst,
×
365
                                                CIDR:       "::/0",
×
366
                                                NextHopIP:  gatewayV6,
×
367
                                                RouteTable: table,
×
368
                                        },
×
369
                                )
×
370
                        }
×
371
                }
372
                if c.config.EnableEipSnat {
×
373
                        cm, err := c.configMapsLister.ConfigMaps(c.config.ExternalGatewayConfigNS).Get(util.ExternalGatewayConfig)
×
374
                        if err == nil {
×
375
                                nextHop := cm.Data["external-gw-addr"]
×
376
                                if nextHop == "" {
×
377
                                        if !externalSubnetExist {
×
378
                                                err = fmt.Errorf("failed to get external subnet %s", c.config.ExternalGatewaySwitch)
×
379
                                                klog.Error(err)
×
380
                                                return err
×
381
                                        }
×
382
                                        nextHop = externalSubnet.Spec.Gateway
×
383
                                        if nextHop == "" {
×
NEW
384
                                                err := fmt.Errorf("subnet %s has no gateway configuration", externalSubnet.Name)
×
NEW
385
                                                klog.Error(err)
×
NEW
386
                                                return err
×
387
                                        }
×
388
                                }
389
                                if strings.Contains(nextHop, "/") {
×
390
                                        nextHop = strings.Split(nextHop, "/")[0]
×
391
                                }
×
392

393
                                lr, err := c.OVNNbClient.GetLogicalRouter(vpc.Name, false)
×
394
                                if err != nil {
×
395
                                        klog.Errorf("failed to get logical router %s: %v", vpc.Name, err)
×
396
                                        return err
×
397
                                }
×
398

399
                                for _, nat := range lr.Nat {
×
400
                                        info, err := c.OVNNbClient.GetNATByUUID(nat)
×
401
                                        if err != nil {
×
402
                                                klog.Errorf("failed to get nat ip info for vpc %s, %v", vpc.Name, err)
×
403
                                                return err
×
404
                                        }
×
405
                                        if info.LogicalIP != "" {
×
406
                                                for table := range staticRouteMapping {
×
407
                                                        staticTargetRoutes = append(
×
408
                                                                staticTargetRoutes,
×
409
                                                                &kubeovnv1.StaticRoute{
×
410
                                                                        Policy:     kubeovnv1.PolicySrc,
×
411
                                                                        CIDR:       info.LogicalIP,
×
412
                                                                        NextHopIP:  nextHop,
×
413
                                                                        RouteTable: table,
×
414
                                                                },
×
415
                                                        )
×
416
                                                }
×
417
                                        }
418
                                }
419
                        }
420
                }
421
        }
422

423
        routeNeedDel, routeNeedAdd, err := diffStaticRoute(staticExistedRoutes, staticTargetRoutes)
×
424
        if err != nil {
×
425
                klog.Errorf("failed to diff vpc %s static route, %v", vpc.Name, err)
×
426
                return err
×
427
        }
×
428

429
        for _, item := range routeNeedDel {
×
430
                klog.Infof("vpc %s del static route: %+v", vpc.Name, item)
×
431
                policy := convertPolicy(item.Policy)
×
432
                if err = c.OVNNbClient.DeleteLogicalRouterStaticRoute(vpc.Name, &item.RouteTable, &policy, item.CIDR, item.NextHopIP); err != nil {
×
433
                        klog.Errorf("del vpc %s static route failed, %v", vpc.Name, err)
×
434
                        return err
×
435
                }
×
436
        }
437

438
        for _, item := range routeNeedAdd {
×
439
                if item.BfdID != "" {
×
440
                        klog.Infof("vpc %s add static ecmp route: %+v", vpc.Name, item)
×
441
                        if err = c.OVNNbClient.AddLogicalRouterStaticRoute(
×
442
                                vpc.Name, item.RouteTable, convertPolicy(item.Policy), item.CIDR, &item.BfdID, nil, item.NextHopIP,
×
443
                        ); err != nil {
×
444
                                klog.Errorf("failed to add bfd static route to vpc %s , %v", vpc.Name, err)
×
445
                                return err
×
446
                        }
×
447
                } else {
×
448
                        klog.Infof("vpc %s add static route: %+v", vpc.Name, item)
×
449
                        if err = c.OVNNbClient.AddLogicalRouterStaticRoute(
×
450
                                vpc.Name, item.RouteTable, convertPolicy(item.Policy), item.CIDR, nil, nil, item.NextHopIP,
×
451
                        ); err != nil {
×
452
                                klog.Errorf("failed to add normal static route to vpc %s , %v", vpc.Name, err)
×
453
                                return err
×
454
                        }
×
455
                }
456
        }
457

458
        // handle policy route
459
        var (
×
460
                policyRouteExisted, policyRouteNeedDel, policyRouteNeedAdd []*kubeovnv1.PolicyRoute
×
461
                policyRouteLogical                                         []*ovnnb.LogicalRouterPolicy
×
462
                externalIDs                                                = map[string]string{"vendor": util.CniTypeName}
×
463
        )
×
464

×
465
        if vpc.Name == c.config.ClusterRouter {
×
466
                policyRouteExisted = reversePolicies(vpc.Annotations[util.VpcLastPolicies])
×
467
                // diff list
×
468
                policyRouteNeedDel, policyRouteNeedAdd = diffPolicyRouteWithExisted(policyRouteExisted, vpc.Spec.PolicyRoutes)
×
469
        } else {
×
470
                if vpc.Spec.PolicyRoutes == nil {
×
471
                        // do not clean default vpc policy routes
×
472
                        if err = c.OVNNbClient.ClearLogicalRouterPolicy(vpc.Name); err != nil {
×
473
                                klog.Errorf("clean all vpc %s policy route failed, %v", vpc.Name, err)
×
474
                                return err
×
475
                        }
×
476
                } else {
×
477
                        policyRouteLogical, err = c.OVNNbClient.ListLogicalRouterPolicies(vpc.Name, -1, nil, true)
×
478
                        if err != nil {
×
479
                                klog.Errorf("failed to get vpc %s policy route list, %v", vpc.Name, err)
×
480
                                return err
×
481
                        }
×
482
                        // diff vpc policy route
483
                        policyRouteNeedDel, policyRouteNeedAdd = diffPolicyRouteWithLogical(policyRouteLogical, vpc.Spec.PolicyRoutes)
×
484
                }
485
        }
486
        // delete policies non-exist
487
        for _, item := range policyRouteNeedDel {
×
488
                klog.Infof("delete policy route for router: %s, priority: %d, match %s", vpc.Name, item.Priority, item.Match)
×
489
                if err = c.OVNNbClient.DeleteLogicalRouterPolicy(vpc.Name, item.Priority, item.Match); err != nil {
×
490
                        klog.Errorf("del vpc %s policy route failed, %v", vpc.Name, err)
×
491
                        return err
×
492
                }
×
493
        }
494
        // add new policies
495
        for _, item := range policyRouteNeedAdd {
×
496
                klog.Infof("add policy route for router: %s, match %s, action %s, nexthop %s, externalID %v", c.config.ClusterRouter, item.Match, string(item.Action), item.NextHopIP, externalIDs)
×
497
                if err = c.OVNNbClient.AddLogicalRouterPolicy(vpc.Name, item.Priority, item.Match, string(item.Action), []string{item.NextHopIP}, nil, externalIDs); err != nil {
×
498
                        klog.Errorf("add policy route to vpc %s failed, %v", vpc.Name, err)
×
499
                        return err
×
500
                }
×
501
        }
502

503
        vpcSubnets, defaultSubnet, err := c.getVpcSubnets(vpc)
×
504
        if err != nil {
×
505
                klog.Error(err)
×
506
                return err
×
507
        }
×
508

509
        vpc.Status.Subnets = vpcSubnets
×
510
        vpc.Status.DefaultLogicalSwitch = defaultSubnet
×
511
        vpc.Status.Router = key
×
512
        vpc.Status.Standby = true
×
513
        vpc.Status.VpcPeerings = newPeers
×
514
        if c.config.EnableLb {
×
515
                vpcLb, err := c.addLoadBalancer(key)
×
516
                if err != nil {
×
517
                        klog.Error(err)
×
518
                        return err
×
519
                }
×
520
                vpc.Status.TCPLoadBalancer = vpcLb.TCPLoadBalancer
×
521
                vpc.Status.TCPSessionLoadBalancer = vpcLb.TCPSessLoadBalancer
×
522
                vpc.Status.UDPLoadBalancer = vpcLb.UDPLoadBalancer
×
523
                vpc.Status.UDPSessionLoadBalancer = vpcLb.UDPSessLoadBalancer
×
524
                vpc.Status.SctpLoadBalancer = vpcLb.SctpLoadBalancer
×
525
                vpc.Status.SctpSessionLoadBalancer = vpcLb.SctpSessLoadBalancer
×
526
        }
527
        bytes, err := vpc.Status.Bytes()
×
528
        if err != nil {
×
529
                klog.Error(err)
×
530
                return err
×
531
        }
×
532
        vpc, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Patch(context.Background(), vpc.Name, types.MergePatchType, bytes, metav1.PatchOptions{}, "status")
×
533
        if err != nil {
×
534
                klog.Error(err)
×
535
                return err
×
536
        }
×
537

538
        if len(vpc.Annotations) != 0 && strings.ToLower(vpc.Annotations[util.VpcLbAnnotation]) == "on" {
×
539
                if err = c.createVpcLb(vpc); err != nil {
×
540
                        klog.Error(err)
×
541
                        return err
×
542
                }
×
543
        } else if err = c.deleteVpcLb(vpc); err != nil {
×
544
                klog.Error(err)
×
545
                return err
×
546
        }
×
547

548
        subnets, err := c.subnetsLister.List(labels.Everything())
×
549
        if err != nil {
×
550
                klog.Error(err)
×
551
                return err
×
552
        }
×
NEW
553
        custVpcEnableExternalEcmp := false
×
554
        for _, subnet := range subnets {
×
555
                if subnet.Spec.Vpc == key {
×
556
                        c.addOrUpdateSubnetQueue.Add(subnet.Name)
×
557
                        if vpc.Name != util.DefaultVpc && vpc.Spec.EnableBfd && subnet.Spec.EnableEcmp {
×
NEW
558
                                custVpcEnableExternalEcmp = true
×
559
                        }
×
560
                }
561
        }
562

NEW
563
        if vpc.Spec.EnableExternal || vpc.Status.EnableExternal {
×
NEW
564
                if err = c.handleUpdateVpcExternal(cachedVpc, custVpcEnableExternalEcmp, externalSubnetExist, externalSubnetGW); err != nil {
×
NEW
565
                        klog.Errorf("failed to handle update external subnet for vpc %s, %v", key, err)
×
NEW
566
                        return err
×
NEW
567
                }
×
568
        }
569

NEW
570
        bfdPortName, bfdPortNodes, err := c.reconcileVpcBfdLRP(vpc)
×
NEW
571
        if err != nil {
×
NEW
572
                klog.Error(err)
×
NEW
573
                return err
×
NEW
574
        }
×
NEW
575
        if vpc.Spec.BFDPort == nil || !vpc.Spec.BFDPort.Enabled {
×
NEW
576
                vpc.Status.BFDPort = kubeovnv1.BFDPortStatus{}
×
NEW
577
        } else {
×
NEW
578
                vpc.Status.BFDPort = kubeovnv1.BFDPortStatus{
×
NEW
579
                        Name:  bfdPortName,
×
NEW
580
                        IP:    vpc.Spec.BFDPort.IP,
×
NEW
581
                        Nodes: bfdPortNodes,
×
NEW
582
                }
×
NEW
583
        }
×
NEW
584
        if _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().
×
NEW
585
                UpdateStatus(context.Background(), vpc, metav1.UpdateOptions{}); err != nil {
×
NEW
586
                klog.Error(err)
×
NEW
587
                return err
×
NEW
588
        }
×
589

NEW
590
        return nil
×
591
}
592

NEW
593
func (c *Controller) handleUpdateVpcExternal(vpc *kubeovnv1.Vpc, custVpcEnableExternalEcmp, defaultExternalSubnetExist bool, externalSubnetGW string) error {
×
NEW
594
        if c.config.EnableEipSnat && vpc.Name == util.DefaultVpc {
×
NEW
595
                klog.Infof("external_gw handle ovn default external gw %s", vpc.Name)
×
NEW
596
                return nil
×
NEW
597
        }
×
598

NEW
599
        if !vpc.Spec.EnableExternal && !vpc.Status.EnableExternal {
×
NEW
600
                // no need to handle external connection
×
NEW
601
                return nil
×
NEW
602
        }
×
603

604
        // handle any vpc external
NEW
605
        if vpc.Spec.EnableExternal && !defaultExternalSubnetExist && vpc.Spec.ExtraExternalSubnets == nil {
×
NEW
606
                // at least have a external subnet
×
NEW
607
                err := fmt.Errorf("failed to get external subnet for enable external vpc %s", vpc.Name)
×
NEW
608
                klog.Error(err)
×
NEW
609
                return err
×
NEW
610
        }
×
611

NEW
612
        if !vpc.Spec.EnableExternal && vpc.Status.EnableExternal {
×
NEW
613
                // just del all external subnets connection
×
NEW
614
                klog.Infof("disconnect default external subnet %s to vpc %s", c.config.ExternalGatewaySwitch, vpc.Name)
×
NEW
615
                if err := c.handleDelVpcExternalSubnet(vpc.Name, c.config.ExternalGatewaySwitch); err != nil {
×
NEW
616
                        klog.Errorf("failed to delete external subnet %s connection for vpc %s, error %v", c.config.ExternalGatewaySwitch, vpc.Name, err)
×
NEW
617
                        return err
×
NEW
618
                }
×
NEW
619
                for _, subnet := range vpc.Status.ExtraExternalSubnets {
×
NEW
620
                        klog.Infof("disconnect external subnet %s to vpc %s", subnet, vpc.Name)
×
NEW
621
                        if err := c.handleDelVpcExternalSubnet(vpc.Name, subnet); err != nil {
×
NEW
622
                                klog.Errorf("failed to delete external subnet %s connection for vpc %s, error %v", subnet, vpc.Name, err)
×
623
                                return err
×
624
                        }
×
625
                }
626
        }
627

NEW
628
        if vpc.Spec.EnableExternal {
×
NEW
629
                if !vpc.Status.EnableExternal {
×
NEW
630
                        // just add external connection
×
NEW
631
                        if vpc.Spec.ExtraExternalSubnets == nil && defaultExternalSubnetExist {
×
NEW
632
                                // only connect default external subnet
×
NEW
633
                                klog.Infof("connect default external subnet %s with vpc %s", c.config.ExternalGatewaySwitch, vpc.Name)
×
NEW
634
                                if err := c.handleAddVpcExternalSubnet(vpc.Name, c.config.ExternalGatewaySwitch); err != nil {
×
NEW
635
                                        klog.Errorf("failed to add external subnet %s connection for vpc %s, error %v", c.config.ExternalGatewaySwitch, vpc.Name, err)
×
636
                                        return err
×
637
                                }
×
638
                        }
639

640
                        // only connect provider network vlan external subnet
NEW
641
                        for _, subnet := range vpc.Spec.ExtraExternalSubnets {
×
NEW
642
                                klog.Infof("connect external subnet %s with vpc %s", subnet, vpc.Name)
×
NEW
643
                                if err := c.handleAddVpcExternalSubnet(vpc.Name, subnet); err != nil {
×
NEW
644
                                        klog.Errorf("failed to add external subnet %s connection for vpc %s, error %v", subnet, vpc.Name, err)
×
645
                                        return err
×
646
                                }
×
647
                        }
648
                }
649

650
                // diff to add
NEW
651
                for _, subnet := range vpc.Spec.ExtraExternalSubnets {
×
NEW
652
                        if !slices.Contains(vpc.Status.ExtraExternalSubnets, subnet) {
×
NEW
653
                                klog.Infof("connect external subnet %s with vpc %s", subnet, vpc.Name)
×
NEW
654
                                if err := c.handleAddVpcExternalSubnet(vpc.Name, subnet); err != nil {
×
NEW
655
                                        klog.Errorf("failed to add external subnet %s connection for vpc %s, error %v", subnet, vpc.Name, err)
×
656
                                        return err
×
657
                                }
×
658
                        }
659
                }
660

661
                // diff to del
NEW
662
                for _, subnet := range vpc.Status.ExtraExternalSubnets {
×
NEW
663
                        if !slices.Contains(vpc.Spec.ExtraExternalSubnets, subnet) {
×
NEW
664
                                klog.Infof("disconnect external subnet %s to vpc %s", subnet, vpc.Name)
×
NEW
665
                                if err := c.handleDelVpcExternalSubnet(vpc.Name, subnet); err != nil {
×
NEW
666
                                        klog.Errorf("failed to delete external subnet %s connection for vpc %s, error %v", subnet, vpc.Name, err)
×
NEW
667
                                        return err
×
NEW
668
                                }
×
669
                        }
670
                }
671
        }
672

673
        // custom vpc enable bfd
NEW
674
        if vpc.Spec.EnableBfd && vpc.Name != util.DefaultVpc && defaultExternalSubnetExist {
×
NEW
675
                // create bfd between lrp and physical switch gw
×
NEW
676
                // bfd status down means current lrp binding chassis node external nic lost external network connectivity
×
NEW
677
                // should switch lrp to another node
×
NEW
678
                lrpEipName := fmt.Sprintf("%s-%s", vpc.Name, c.config.ExternalGatewaySwitch)
×
NEW
679
                v4ExtGw, _ := util.SplitStringIP(externalSubnetGW)
×
NEW
680
                // TODO: dualstack
×
NEW
681
                if _, err := c.OVNNbClient.CreateBFD(lrpEipName, v4ExtGw, c.config.BfdMinRx, c.config.BfdMinTx, c.config.BfdDetectMult, nil); err != nil {
×
NEW
682
                        klog.Error(err)
×
NEW
683
                        return err
×
684
                }
×
685
                // TODO: support multi external nic
NEW
686
                if custVpcEnableExternalEcmp {
×
NEW
687
                        klog.Infof("remove normal static ecmp route for vpc %s", vpc.Name)
×
NEW
688
                        // auto remove normal type static route, if using ecmp based bfd
×
NEW
689
                        if err := c.reconcileCustomVpcDelNormalStaticRoute(vpc.Name); err != nil {
×
NEW
690
                                klog.Errorf("failed to reconcile del vpc %q normal static route", vpc.Name)
×
691
                                return err
×
692
                        }
×
693
                }
694
        }
695

NEW
696
        if !vpc.Spec.EnableBfd && vpc.Status.EnableBfd {
×
NEW
697
                lrpEipName := fmt.Sprintf("%s-%s", vpc.Name, c.config.ExternalGatewaySwitch)
×
NEW
698
                if err := c.OVNNbClient.DeleteBFDByDstIP(lrpEipName, ""); err != nil {
×
NEW
699
                        klog.Error(err)
×
NEW
700
                        return err
×
NEW
701
                }
×
NEW
702
                if err := c.handleDeleteVpcStaticRoute(vpc.Name); err != nil {
×
NEW
703
                        klog.Errorf("failed to delete bfd route for vpc %s, error %v", vpc.Name, err)
×
NEW
704
                        return err
×
705
                }
×
706
        }
707

NEW
708
        if err := c.updateVpcExternalStatus(vpc.Name, vpc.Spec.EnableExternal); err != nil {
×
NEW
709
                klog.Errorf("failed to update vpc external subnets status, %v", err)
×
710
                return err
×
711
        }
×
712
        return nil
×
713
}
714

715
func (c *Controller) reconcileVpcBfdLRP(vpc *kubeovnv1.Vpc) (string, []string, error) {
×
716
        portName := "bfd@" + vpc.Name
×
717
        if vpc.Spec.BFDPort == nil || !vpc.Spec.BFDPort.Enabled {
×
718
                if err := c.OVNNbClient.DeleteLogicalRouterPort(portName); err != nil {
×
719
                        err = fmt.Errorf("failed to delete BFD LRP %s: %w", portName, err)
×
720
                        klog.Error(err)
×
721
                        return portName, nil, err
×
722
                }
×
723
                if err := c.OVNNbClient.DeleteHAChassisGroup(portName); err != nil {
×
724
                        err = fmt.Errorf("failed to delete HA chassis group %s: %w", portName, err)
×
725
                        klog.Error(err)
×
726
                        return portName, nil, err
×
727
                }
×
728
                return portName, nil, nil
×
729
        }
730

731
        var err error
×
732
        chassisCount := 3
×
733
        selector := labels.Everything()
×
734
        if vpc.Spec.BFDPort.NodeSelector != nil {
×
735
                chassisCount = math.MaxInt
×
736
                if selector, err = metav1.LabelSelectorAsSelector(vpc.Spec.BFDPort.NodeSelector); err != nil {
×
737
                        err = fmt.Errorf("failed to parse node selector %q: %w", vpc.Spec.BFDPort.NodeSelector.String(), err)
×
738
                        klog.Error(err)
×
739
                        return portName, nil, err
×
740
                }
×
741
        }
742

743
        nodes, err := c.nodesLister.List(selector)
×
744
        if err != nil {
×
745
                err = fmt.Errorf("failed to list nodes with selector %q: %w", vpc.Spec.BFDPort.NodeSelector, err)
×
746
                klog.Error(err)
×
747
                return portName, nil, err
×
748
        }
×
749
        if len(nodes) == 0 {
×
750
                err = fmt.Errorf("no nodes found by selector %q", selector.String())
×
751
                klog.Error(err)
×
752
                return portName, nil, err
×
753
        }
×
754

755
        nodeNames := make([]string, 0, len(nodes))
×
756
        chassisCount = min(chassisCount, len(nodes))
×
757
        chassisNames := make([]string, 0, chassisCount)
×
758
        for _, nodes := range nodes[:chassisCount] {
×
759
                chassis, err := c.OVNSbClient.GetChassisByHost(nodes.Name)
×
760
                if err != nil {
×
761
                        err = fmt.Errorf("failed to get chassis of node %s: %w", nodes.Name, err)
×
762
                        klog.Error(err)
×
763
                        return portName, nil, err
×
764
                }
×
765
                chassisNames = append(chassisNames, chassis.Name)
×
766
                nodeNames = append(nodeNames, nodes.Name)
×
767
        }
768

769
        networks := strings.Split(vpc.Spec.BFDPort.IP, ",")
×
770
        if err = c.OVNNbClient.CreateLogicalRouterPort(vpc.Name, portName, "", networks); err != nil {
×
771
                klog.Error(err)
×
772
                return portName, nil, err
×
773
        }
×
774
        if err = c.OVNNbClient.UpdateLogicalRouterPortNetworks(portName, networks); err != nil {
×
775
                klog.Error(err)
×
776
                return portName, nil, err
×
777
        }
×
778
        if err = c.OVNNbClient.UpdateLogicalRouterPortOptions(portName, map[string]string{"bfd-only": "true"}); err != nil {
×
779
                klog.Error(err)
×
780
                return portName, nil, err
×
781
        }
×
782
        if err = c.OVNNbClient.CreateHAChassisGroup(portName, chassisNames, map[string]string{"lrp": portName}); err != nil {
×
783
                klog.Error(err)
×
784
                return portName, nil, err
×
785
        }
×
786
        if err = c.OVNNbClient.SetLogicalRouterPortHAChassisGroup(portName, portName); err != nil {
×
787
                klog.Error(err)
×
788
                return portName, nil, err
×
789
        }
×
790

791
        return portName, nodeNames, nil
×
792
}
793

794
func (c *Controller) addPolicyRouteToVpc(vpcName string, policy *kubeovnv1.PolicyRoute, externalIDs map[string]string) error {
×
795
        var (
×
796
                nextHops []string
×
797
                err      error
×
798
        )
×
799

×
800
        if policy.NextHopIP != "" {
×
801
                nextHops = strings.Split(policy.NextHopIP, ",")
×
802
        }
×
803

804
        if err = c.OVNNbClient.AddLogicalRouterPolicy(vpcName, policy.Priority, policy.Match, string(policy.Action), nextHops, nil, externalIDs); err != nil {
×
805
                klog.Errorf("add policy route to vpc %s failed, %v", vpcName, err)
×
806
                return err
×
807
        }
×
808
        return nil
×
809
}
810

811
func buildExternalIDsMapKey(match, action string, priority int) string {
×
812
        return fmt.Sprintf("%s-%s-%d", match, action, priority)
×
813
}
×
814

815
func (c *Controller) batchAddPolicyRouteToVpc(name string, policies []*kubeovnv1.PolicyRoute, externalIDs map[string]map[string]string) error {
×
816
        if len(policies) == 0 {
×
817
                return nil
×
818
        }
×
819
        start := time.Now()
×
820
        routerPolicies := make([]*ovnnb.LogicalRouterPolicy, 0, len(policies))
×
821
        for _, policy := range policies {
×
822
                var nextHops []string
×
823
                if policy.NextHopIP != "" {
×
824
                        nextHops = strings.Split(policy.NextHopIP, ",")
×
825
                }
×
826
                routerPolicies = append(routerPolicies, &ovnnb.LogicalRouterPolicy{
×
827
                        Priority:    policy.Priority,
×
828
                        Nexthops:    nextHops,
×
829
                        Action:      string(policy.Action),
×
830
                        Match:       policy.Match,
×
831
                        ExternalIDs: externalIDs[buildExternalIDsMapKey(policy.Match, string(policy.Action), policy.Priority)],
×
832
                })
×
833
        }
834

835
        if err := c.OVNNbClient.BatchAddLogicalRouterPolicy(name, routerPolicies...); err != nil {
×
836
                klog.Errorf("batch add policy route to vpc %s failed, %v", name, err)
×
837
                return err
×
838
        }
×
839
        klog.Infof("take to %v batch add policy route to vpc %s policies %d", time.Since(start), name, len(policies))
×
840
        return nil
×
841
}
842

843
func (c *Controller) deletePolicyRouteFromVpc(vpcName string, priority int, match string) error {
×
844
        var (
×
845
                vpc, cachedVpc *kubeovnv1.Vpc
×
846
                err            error
×
847
        )
×
848

×
849
        if err = c.OVNNbClient.DeleteLogicalRouterPolicy(vpcName, priority, match); err != nil {
×
850
                klog.Error(err)
×
851
                return err
×
852
        }
×
853

854
        cachedVpc, err = c.vpcsLister.Get(vpcName)
×
855
        if err != nil {
×
856
                if k8serrors.IsNotFound(err) {
×
857
                        return nil
×
858
                }
×
859
                klog.Error(err)
×
860
                return err
×
861
        }
862
        vpc = cachedVpc.DeepCopy()
×
863
        // make sure custom policies not be deleted
×
864
        _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Update(context.Background(), vpc, metav1.UpdateOptions{})
×
865
        if err != nil {
×
866
                klog.Error(err)
×
867
                return err
×
868
        }
×
869
        return nil
×
870
}
871

872
func (c *Controller) batchDeletePolicyRouteFromVpc(name string, policies []*kubeovnv1.PolicyRoute) error {
×
873
        var (
×
874
                vpc, cachedVpc *kubeovnv1.Vpc
×
875
                err            error
×
876
        )
×
877

×
878
        start := time.Now()
×
879
        routerPolicies := make([]*ovnnb.LogicalRouterPolicy, 0, len(policies))
×
880
        for _, policy := range policies {
×
881
                routerPolicies = append(routerPolicies, &ovnnb.LogicalRouterPolicy{
×
882
                        Priority: policy.Priority,
×
883
                        Match:    policy.Match,
×
884
                })
×
885
        }
×
886

887
        if err = c.OVNNbClient.BatchDeleteLogicalRouterPolicy(name, routerPolicies); err != nil {
×
888
                return err
×
889
        }
×
890
        klog.V(3).Infof("take to %v batch delete policy route from vpc %s policies %d", time.Since(start), name, len(policies))
×
891

×
892
        cachedVpc, err = c.vpcsLister.Get(name)
×
893
        if err != nil {
×
894
                if k8serrors.IsNotFound(err) {
×
895
                        return nil
×
896
                }
×
897
                klog.Error(err)
×
898
                return err
×
899
        }
900
        vpc = cachedVpc.DeepCopy()
×
901
        // make sure custom policies not be deleted
×
902
        _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Update(context.Background(), vpc, metav1.UpdateOptions{})
×
903
        if err != nil {
×
904
                klog.Error(err)
×
905
                return err
×
906
        }
×
907
        return nil
×
908
}
909

910
func (c *Controller) addStaticRouteToVpc(name string, route *kubeovnv1.StaticRoute) error {
×
911
        if route.BfdID != "" {
×
912
                klog.Infof("vpc %s add static ecmp route: %+v", name, route)
×
913
                if err := c.OVNNbClient.AddLogicalRouterStaticRoute(
×
914
                        name, route.RouteTable, convertPolicy(route.Policy), route.CIDR, &route.BfdID, nil, route.NextHopIP,
×
915
                ); err != nil {
×
916
                        klog.Errorf("failed to add bfd static route to vpc %s , %v", name, err)
×
917
                        return err
×
918
                }
×
919
        } else {
×
920
                klog.Infof("vpc %s add static route: %+v", name, route)
×
921
                if err := c.OVNNbClient.AddLogicalRouterStaticRoute(
×
922
                        name, route.RouteTable, convertPolicy(route.Policy), route.CIDR, nil, nil, route.NextHopIP,
×
923
                ); err != nil {
×
924
                        klog.Errorf("failed to add normal static route to vpc %s , %v", name, err)
×
925
                        return err
×
926
                }
×
927
        }
928
        return nil
×
929
}
930

931
func (c *Controller) deleteStaticRouteFromVpc(name, table, cidr, nextHop string, policy kubeovnv1.RoutePolicy) error {
×
932
        var (
×
933
                policyStr string
×
934
                err       error
×
935
        )
×
936

×
937
        policyStr = convertPolicy(policy)
×
938
        if err = c.OVNNbClient.DeleteLogicalRouterStaticRoute(name, &table, &policyStr, cidr, nextHop); err != nil {
×
939
                klog.Errorf("del vpc %s static route failed, %v", name, err)
×
940
                return err
×
941
        }
×
942

943
        return nil
×
944
}
945

946
func (c *Controller) batchDeleteStaticRouteFromVpc(name string, staticRoutes []*kubeovnv1.StaticRoute) error {
×
947
        var (
×
948
                vpc, cachedVpc *kubeovnv1.Vpc
×
949
                err            error
×
950
        )
×
951
        start := time.Now()
×
952
        routeCount := len(staticRoutes)
×
953
        delRoutes := make([]*ovnnb.LogicalRouterStaticRoute, 0, routeCount)
×
954
        for _, sr := range staticRoutes {
×
955
                policyStr := convertPolicy(sr.Policy)
×
956
                newRoute := &ovnnb.LogicalRouterStaticRoute{
×
957
                        RouteTable: sr.RouteTable,
×
958
                        Nexthop:    sr.NextHopIP,
×
959
                        Policy:     &policyStr,
×
960
                        IPPrefix:   sr.CIDR,
×
961
                }
×
962
                delRoutes = append(delRoutes, newRoute)
×
963
        }
×
964
        if err = c.OVNNbClient.BatchDeleteLogicalRouterStaticRoute(name, delRoutes); err != nil {
×
965
                klog.Errorf("batch del vpc %s static route %d failed, %v", name, routeCount, err)
×
966
                return err
×
967
        }
×
968
        klog.V(3).Infof("take to %v batch delete static route from vpc %s static routes %d", time.Since(start), name, len(delRoutes))
×
969

×
970
        cachedVpc, err = c.vpcsLister.Get(name)
×
971
        if err != nil {
×
972
                if k8serrors.IsNotFound(err) {
×
973
                        return nil
×
974
                }
×
975
                klog.Error(err)
×
976
                return err
×
977
        }
978
        vpc = cachedVpc.DeepCopy()
×
979
        // make sure custom policies not be deleted
×
980
        _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Update(context.Background(), vpc, metav1.UpdateOptions{})
×
981
        if err != nil {
×
982
                klog.Error(err)
×
983
                return err
×
984
        }
×
985
        return nil
×
986
}
987

988
func diffPolicyRouteWithExisted(exists, target []*kubeovnv1.PolicyRoute) ([]*kubeovnv1.PolicyRoute, []*kubeovnv1.PolicyRoute) {
×
989
        var (
×
990
                dels, adds []*kubeovnv1.PolicyRoute
×
991
                existsMap  map[string]*kubeovnv1.PolicyRoute
×
992
                key        string
×
993
                ok         bool
×
994
        )
×
995

×
996
        existsMap = make(map[string]*kubeovnv1.PolicyRoute, len(exists))
×
997
        for _, item := range exists {
×
998
                existsMap[getPolicyRouteItemKey(item)] = item
×
999
        }
×
1000
        // load policies to add
1001
        for _, item := range target {
×
1002
                key = getPolicyRouteItemKey(item)
×
1003

×
1004
                if _, ok = existsMap[key]; ok {
×
1005
                        delete(existsMap, key)
×
1006
                } else {
×
1007
                        adds = append(adds, item)
×
1008
                }
×
1009
        }
1010
        // load policies to delete
1011
        for _, item := range existsMap {
×
1012
                dels = append(dels, item)
×
1013
        }
×
1014
        return dels, adds
×
1015
}
1016

1017
func diffPolicyRouteWithLogical(exists []*ovnnb.LogicalRouterPolicy, target []*kubeovnv1.PolicyRoute) ([]*kubeovnv1.PolicyRoute, []*kubeovnv1.PolicyRoute) {
×
1018
        var (
×
1019
                dels, adds []*kubeovnv1.PolicyRoute
×
1020
                existsMap  map[string]*kubeovnv1.PolicyRoute
×
1021
                key        string
×
1022
                ok         bool
×
1023
        )
×
1024
        existsMap = make(map[string]*kubeovnv1.PolicyRoute, len(exists))
×
1025

×
1026
        for _, item := range exists {
×
1027
                policy := &kubeovnv1.PolicyRoute{
×
1028
                        Priority: item.Priority,
×
1029
                        Match:    item.Match,
×
1030
                        Action:   kubeovnv1.PolicyRouteAction(item.Action),
×
1031
                }
×
1032
                existsMap[getPolicyRouteItemKey(policy)] = policy
×
1033
        }
×
1034

1035
        for _, item := range target {
×
1036
                key = getPolicyRouteItemKey(item)
×
1037

×
1038
                if _, ok = existsMap[key]; ok {
×
1039
                        delete(existsMap, key)
×
1040
                } else {
×
1041
                        adds = append(adds, item)
×
1042
                }
×
1043
        }
1044

1045
        for _, item := range existsMap {
×
1046
                dels = append(dels, item)
×
1047
        }
×
1048
        return dels, adds
×
1049
}
1050

1051
func getPolicyRouteItemKey(item *kubeovnv1.PolicyRoute) (key string) {
×
1052
        return fmt.Sprintf("%d:%s:%s:%s", item.Priority, item.Match, item.Action, item.NextHopIP)
×
1053
}
×
1054

1055
func diffStaticRoute(exist []*ovnnb.LogicalRouterStaticRoute, target []*kubeovnv1.StaticRoute) (routeNeedDel, routeNeedAdd []*kubeovnv1.StaticRoute, err error) {
×
1056
        existRouteMap := make(map[string]*kubeovnv1.StaticRoute, len(exist))
×
1057
        for _, item := range exist {
×
1058
                policy := kubeovnv1.PolicyDst
×
1059
                if item.Policy != nil && *item.Policy == ovnnb.LogicalRouterStaticRoutePolicySrcIP {
×
1060
                        policy = kubeovnv1.PolicySrc
×
1061
                }
×
1062
                route := &kubeovnv1.StaticRoute{
×
1063
                        Policy:     policy,
×
1064
                        CIDR:       item.IPPrefix,
×
1065
                        NextHopIP:  item.Nexthop,
×
1066
                        RouteTable: item.RouteTable,
×
1067
                        ECMPMode:   util.StaticRouteBfdEcmp,
×
1068
                }
×
1069
                if item.BFD != nil {
×
1070
                        route.BfdID = *item.BFD
×
1071
                }
×
1072
                existRouteMap[getStaticRouteItemKey(route)] = route
×
1073
        }
1074

1075
        for _, item := range target {
×
1076
                key := getStaticRouteItemKey(item)
×
1077
                if _, ok := existRouteMap[key]; ok {
×
1078
                        delete(existRouteMap, key)
×
1079
                } else {
×
1080
                        routeNeedAdd = append(routeNeedAdd, item)
×
1081
                }
×
1082
        }
1083
        for _, item := range existRouteMap {
×
1084
                routeNeedDel = append(routeNeedDel, item)
×
1085
        }
×
1086
        return
×
1087
}
1088

1089
func getStaticRouteItemKey(item *kubeovnv1.StaticRoute) string {
×
1090
        var key string
×
1091
        if item.Policy == kubeovnv1.PolicyDst {
×
1092
                key = fmt.Sprintf("%s:dst:%s=>%s", item.RouteTable, item.CIDR, item.NextHopIP)
×
1093
        } else {
×
1094
                key = fmt.Sprintf("%s:src:%s=>%s", item.RouteTable, item.CIDR, item.NextHopIP)
×
1095
        }
×
1096
        return key
×
1097
}
1098

1099
func (c *Controller) formatVpc(vpc *kubeovnv1.Vpc) (*kubeovnv1.Vpc, error) {
×
1100
        var changed bool
×
1101
        for _, item := range vpc.Spec.StaticRoutes {
×
1102
                // check policy
×
1103
                if item.Policy == "" {
×
1104
                        item.Policy = kubeovnv1.PolicyDst
×
1105
                        changed = true
×
1106
                }
×
1107
                if item.Policy != kubeovnv1.PolicyDst && item.Policy != kubeovnv1.PolicySrc {
×
1108
                        return nil, fmt.Errorf("unknown policy type: %q", item.Policy)
×
1109
                }
×
1110
                // check cidr
1111
                if strings.Contains(item.CIDR, "/") {
×
1112
                        if _, _, err := net.ParseCIDR(item.CIDR); err != nil {
×
1113
                                return nil, fmt.Errorf("invalid cidr %q: %w", item.CIDR, err)
×
1114
                        }
×
1115
                } else if ip := net.ParseIP(item.CIDR); ip == nil {
×
1116
                        return nil, fmt.Errorf("invalid ip %q", item.CIDR)
×
1117
                }
×
1118
                // check next hop ip
1119
                if ip := net.ParseIP(item.NextHopIP); ip == nil {
×
1120
                        return nil, fmt.Errorf("invalid next hop ip %q", item.NextHopIP)
×
1121
                }
×
1122
        }
1123

1124
        for _, route := range vpc.Spec.PolicyRoutes {
×
1125
                if route.Action != kubeovnv1.PolicyRouteActionReroute {
×
1126
                        if route.NextHopIP != "" {
×
1127
                                route.NextHopIP = ""
×
1128
                                changed = true
×
1129
                        }
×
1130
                } else {
×
1131
                        // ecmp policy route may reroute to multiple next hop ips
×
1132
                        for ipStr := range strings.SplitSeq(route.NextHopIP, ",") {
×
1133
                                if ip := net.ParseIP(ipStr); ip == nil {
×
1134
                                        err := fmt.Errorf("invalid next hop ips: %s", route.NextHopIP)
×
1135
                                        klog.Error(err)
×
1136
                                        return nil, err
×
1137
                                }
×
1138
                        }
1139
                }
1140
        }
1141

1142
        if vpc.DeletionTimestamp.IsZero() && !slices.Contains(vpc.GetFinalizers(), util.KubeOVNControllerFinalizer) {
×
1143
                controllerutil.AddFinalizer(vpc, util.KubeOVNControllerFinalizer)
×
1144
                changed = true
×
1145
        }
×
1146

1147
        if !vpc.DeletionTimestamp.IsZero() && len(vpc.Status.Subnets) == 0 {
×
1148
                controllerutil.RemoveFinalizer(vpc, util.KubeOVNControllerFinalizer)
×
1149
                changed = true
×
1150
        }
×
1151

1152
        if changed {
×
1153
                newVpc, err := c.config.KubeOvnClient.KubeovnV1().Vpcs().Update(context.Background(), vpc, metav1.UpdateOptions{})
×
1154
                if err != nil {
×
1155
                        klog.Errorf("failed to update vpc %s: %v", vpc.Name, err)
×
1156
                        return nil, err
×
1157
                }
×
1158
                return newVpc, nil
×
1159
        }
1160

1161
        return vpc, nil
×
1162
}
1163

1164
func convertPolicies(list []*kubeovnv1.PolicyRoute) string {
×
1165
        if list == nil {
×
1166
                return ""
×
1167
        }
×
1168

1169
        var (
×
1170
                res []byte
×
1171
                err error
×
1172
        )
×
1173

×
1174
        if res, err = json.Marshal(list); err != nil {
×
1175
                klog.Errorf("failed to serialize policy routes %v , reason : %v", list, err)
×
1176
                return ""
×
1177
        }
×
1178
        return string(res)
×
1179
}
1180

1181
func reversePolicies(origin string) []*kubeovnv1.PolicyRoute {
×
1182
        if origin == "" {
×
1183
                return nil
×
1184
        }
×
1185

1186
        var (
×
1187
                list []*kubeovnv1.PolicyRoute
×
1188
                err  error
×
1189
        )
×
1190

×
1191
        if err = json.Unmarshal([]byte(origin), &list); err != nil {
×
1192
                klog.Errorf("failed to deserialize policy routes %v , reason : %v", list, err)
×
1193
                return nil
×
1194
        }
×
1195
        return list
×
1196
}
1197

1198
func convertPolicy(origin kubeovnv1.RoutePolicy) string {
×
1199
        if origin == kubeovnv1.PolicyDst {
×
1200
                return ovnnb.LogicalRouterStaticRoutePolicyDstIP
×
1201
        }
×
1202
        return ovnnb.LogicalRouterStaticRoutePolicySrcIP
×
1203
}
1204

1205
func reversePolicy(origin ovnnb.LogicalRouterStaticRoutePolicy) kubeovnv1.RoutePolicy {
×
1206
        if origin == ovnnb.LogicalRouterStaticRoutePolicyDstIP {
×
1207
                return kubeovnv1.PolicyDst
×
1208
        }
×
1209
        return kubeovnv1.PolicySrc
×
1210
}
1211

1212
func (c *Controller) getVpcSubnets(vpc *kubeovnv1.Vpc) (subnets []string, defaultSubnet string, err error) {
×
1213
        subnets = []string{}
×
1214
        allSubnets, err := c.subnetsLister.List(labels.Everything())
×
1215
        if err != nil {
×
1216
                klog.Error(err)
×
1217
                return nil, "", err
×
1218
        }
×
1219

1220
        for _, subnet := range allSubnets {
×
1221
                if subnet.Spec.Vpc != vpc.Name || !subnet.DeletionTimestamp.IsZero() || !isOvnSubnet(subnet) {
×
1222
                        continue
×
1223
                }
1224

1225
                subnets = append(subnets, subnet.Name)
×
1226
                if subnet.Spec.Default {
×
1227
                        defaultSubnet = subnet.Name
×
1228
                }
×
1229

1230
                if vpc.Name != util.DefaultVpc && vpc.Spec.DefaultSubnet != "" && vpc.Spec.DefaultSubnet == subnet.Name {
×
1231
                        defaultSubnet = vpc.Spec.DefaultSubnet
×
1232
                }
×
1233
        }
1234
        return
×
1235
}
1236

1237
// createVpcRouter create router to connect logical switches in vpc
1238
func (c *Controller) createVpcRouter(lr string) error {
×
1239
        if err := c.OVNNbClient.CreateLogicalRouter(lr); err != nil {
×
1240
                klog.Errorf("create logical router %s failed: %v", lr, err)
×
1241
                return err
×
1242
        }
×
1243

1244
        vpcRouter, err := c.OVNNbClient.GetLogicalRouter(lr, false)
×
1245
        if err != nil {
×
1246
                klog.Errorf("get logical router %s failed: %v", lr, err)
×
1247
                return err
×
1248
        }
×
1249

1250
        vpcRouter.Options = map[string]string{"always_learn_from_arp_request": "false", "dynamic_neigh_routers": "true", "mac_binding_age_threshold": "300"}
×
1251
        err = c.OVNNbClient.UpdateLogicalRouter(vpcRouter, &vpcRouter.Options)
×
1252
        if err != nil {
×
1253
                klog.Errorf("update logical router %s failed: %v", lr, err)
×
1254
                return err
×
1255
        }
×
1256
        return nil
×
1257
}
1258

1259
// deleteVpcRouter delete router to connect logical switches in vpc
1260
func (c *Controller) deleteVpcRouter(lr string) error {
×
1261
        return c.OVNNbClient.DeleteLogicalRouter(lr)
×
1262
}
×
1263

1264
func (c *Controller) handleAddVpcExternalSubnet(key, subnet string) error {
×
1265
        cachedSubnet, err := c.subnetsLister.Get(subnet)
×
1266
        if err != nil {
×
1267
                klog.Error(err)
×
1268
                return err
×
1269
        }
×
1270
        lrpEipName := fmt.Sprintf("%s-%s", key, subnet)
×
1271
        cachedEip, err := c.ovnEipsLister.Get(lrpEipName)
×
1272
        var needCreateEip bool
×
1273
        if err != nil {
×
1274
                if !k8serrors.IsNotFound(err) {
×
1275
                        klog.Error(err)
×
1276
                        return err
×
1277
                }
×
1278
                needCreateEip = true
×
1279
        }
1280
        var v4ip, v6ip, mac string
×
1281
        klog.V(3).Infof("create vpc lrp eip %s", lrpEipName)
×
1282
        if needCreateEip {
×
1283
                if v4ip, v6ip, mac, err = c.acquireIPAddress(subnet, lrpEipName, lrpEipName); err != nil {
×
1284
                        klog.Errorf("failed to acquire ip address for lrp eip %s, %v", lrpEipName, err)
×
1285
                        return err
×
1286
                }
×
1287
                if err := c.createOrUpdateOvnEipCR(lrpEipName, subnet, v4ip, v6ip, mac, util.OvnEipTypeLRP); err != nil {
×
1288
                        klog.Errorf("failed to create ovn eip for lrp %s: %v", lrpEipName, err)
×
1289
                        return err
×
1290
                }
×
1291
        } else {
×
1292
                v4ip = cachedEip.Spec.V4Ip
×
1293
                mac = cachedEip.Spec.MacAddress
×
1294
        }
×
1295
        if v4ip == "" || mac == "" {
×
1296
                err := fmt.Errorf("lrp '%s' ip or mac should not be empty", lrpEipName)
×
1297
                klog.Error(err)
×
1298
                return err
×
1299
        }
×
1300
        // init lrp gw chassis group
1301
        chassises := []string{}
×
1302
        sel, _ := metav1.LabelSelectorAsSelector(&metav1.LabelSelector{MatchLabels: map[string]string{util.ExGatewayLabel: "true"}})
×
1303
        gwNodes, err := c.nodesLister.List(sel)
×
1304
        if err != nil {
×
1305
                klog.Errorf("failed to list external gw nodes, %v", err)
×
1306
                return err
×
1307
        }
×
1308
        for _, gwNode := range gwNodes {
×
1309
                annoChassisName := gwNode.Annotations[util.ChassisAnnotation]
×
1310
                if annoChassisName == "" {
×
1311
                        err := fmt.Errorf("node %s has no chassis annotation, kube-ovn-cni not ready", gwNode.Name)
×
1312
                        klog.Error(err)
×
1313
                        return err
×
1314
                }
×
1315
                klog.Infof("get node %s chassis: %s", gwNode.Name, annoChassisName)
×
1316
                chassis, err := c.OVNSbClient.GetChassis(annoChassisName, false)
×
1317
                if err != nil {
×
1318
                        klog.Errorf("failed to get node %s chassis: %s, %v", gwNode.Name, annoChassisName, err)
×
1319
                        return err
×
1320
                }
×
1321
                chassises = append(chassises, chassis.Name)
×
1322
        }
1323

1324
        if len(chassises) == 0 {
×
1325
                err := errors.New("no external gw nodes")
×
1326
                klog.Error(err)
×
1327
                return err
×
1328
        }
×
1329

1330
        v4ipCidr, err := util.GetIPAddrWithMask(v4ip, cachedSubnet.Spec.CIDRBlock)
×
1331
        if err != nil {
×
1332
                klog.Error(err)
×
1333
                return err
×
1334
        }
×
1335
        lspName := fmt.Sprintf("%s-%s", subnet, key)
×
1336
        lrpName := fmt.Sprintf("%s-%s", key, subnet)
×
1337

×
1338
        if err := c.OVNNbClient.CreateLogicalPatchPort(subnet, key, lspName, lrpName, v4ipCidr, mac, chassises...); err != nil {
×
1339
                klog.Errorf("failed to connect router '%s' to external: %v", key, err)
×
1340
                return err
×
1341
        }
×
1342
        return nil
×
1343
}
1344

1345
func (c *Controller) handleDeleteVpcStaticRoute(key string) error {
×
1346
        vpc, err := c.vpcsLister.Get(key)
×
1347
        if err != nil {
×
1348
                if k8serrors.IsNotFound(err) {
×
1349
                        return nil
×
1350
                }
×
1351
                klog.Errorf("failed to get vpc %s, %v", key, err)
×
1352
                return err
×
1353
        }
1354
        needUpdate := false
×
1355
        newStaticRoutes := make([]*kubeovnv1.StaticRoute, 0, len(vpc.Spec.StaticRoutes))
×
1356
        for _, route := range vpc.Spec.StaticRoutes {
×
1357
                if route.ECMPMode != util.StaticRouteBfdEcmp {
×
1358
                        newStaticRoutes = append(newStaticRoutes, route)
×
1359
                        needUpdate = true
×
1360
                }
×
1361
        }
1362
        // keep non ecmp bfd routes
1363
        vpc.Spec.StaticRoutes = newStaticRoutes
×
1364
        if needUpdate {
×
1365
                if _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Update(context.Background(), vpc, metav1.UpdateOptions{}); err != nil {
×
1366
                        klog.Errorf("failed to update vpc spec static route %s, %v", vpc.Name, err)
×
1367
                        return err
×
1368
                }
×
1369
        }
1370
        if err = c.patchVpcBfdStatus(vpc.Name); err != nil {
×
1371
                klog.Errorf("failed to patch vpc %s, %v", vpc.Name, err)
×
1372
                return err
×
1373
        }
×
1374
        return nil
×
1375
}
1376

1377
func (c *Controller) handleDelVpcExternalSubnet(key, subnet string) error {
×
1378
        lspName := fmt.Sprintf("%s-%s", subnet, key)
×
1379
        lrpName := fmt.Sprintf("%s-%s", key, subnet)
×
NEW
1380
        klog.Infof("delete vpc lrp %s", lrpName)
×
1381
        if err := c.OVNNbClient.RemoveLogicalPatchPort(lspName, lrpName); err != nil {
×
1382
                klog.Errorf("failed to disconnect router '%s' to external, %v", key, err)
×
1383
                return err
×
1384
        }
×
1385
        if err := c.config.KubeOvnClient.KubeovnV1().OvnEips().Delete(context.Background(), lrpName, metav1.DeleteOptions{}); err != nil {
×
1386
                if !k8serrors.IsNotFound(err) {
×
1387
                        klog.Errorf("failed to delete ovn eip %s, %v", lrpName, err)
×
1388
                        return err
×
1389
                }
×
1390
        }
1391
        if err := c.OVNNbClient.DeleteBFDByDstIP(lrpName, ""); err != nil {
×
1392
                klog.Error(err)
×
1393
                return err
×
1394
        }
×
1395
        return nil
×
1396
}
1397

1398
func (c *Controller) patchVpcBfdStatus(key string) error {
×
1399
        cachedVpc, err := c.vpcsLister.Get(key)
×
1400
        if err != nil {
×
1401
                if k8serrors.IsNotFound(err) {
×
1402
                        return nil
×
1403
                }
×
1404
                klog.Errorf("failed to get vpc %s, %v", key, err)
×
1405
                return err
×
1406
        }
1407

1408
        if cachedVpc.Status.EnableBfd != cachedVpc.Spec.EnableBfd {
×
1409
                status := cachedVpc.Status.DeepCopy()
×
1410
                status.EnableExternal = cachedVpc.Spec.EnableExternal
×
1411
                status.EnableBfd = cachedVpc.Spec.EnableBfd
×
1412
                bytes, err := status.Bytes()
×
1413
                if err != nil {
×
1414
                        klog.Errorf("failed to marshal vpc status: %v", err)
×
1415
                        return err
×
1416
                }
×
1417
                if _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Patch(context.Background(),
×
1418
                        cachedVpc.Name, types.MergePatchType, bytes, metav1.PatchOptions{}, "status"); err != nil {
×
1419
                        klog.Error(err)
×
1420
                        return err
×
1421
                }
×
1422
        }
1423
        return nil
×
1424
}
1425

1426
func (c *Controller) getRouteTablesByVpc(vpc *kubeovnv1.Vpc) map[string][]*kubeovnv1.StaticRoute {
×
1427
        rtbs := make(map[string][]*kubeovnv1.StaticRoute)
×
1428
        for _, route := range vpc.Spec.StaticRoutes {
×
1429
                rtbs[route.RouteTable] = append(rtbs[route.RouteTable], route)
×
1430
        }
×
1431
        return rtbs
×
1432
}
1433

NEW
1434
func (c *Controller) updateVpcExternalStatus(key string, enableExternal bool) error {
×
1435
        cachedVpc, err := c.vpcsLister.Get(key)
×
1436
        if err != nil {
×
1437
                klog.Errorf("failed to get vpc %s, %v", key, err)
×
1438
                return err
×
1439
        }
×
1440
        vpc := cachedVpc.DeepCopy()
×
NEW
1441
        vpc.Status.EnableExternal = vpc.Spec.EnableExternal
×
NEW
1442
        vpc.Status.EnableBfd = vpc.Spec.EnableBfd
×
NEW
1443

×
NEW
1444
        if enableExternal {
×
1445
                sort.Strings(vpc.Spec.ExtraExternalSubnets)
×
1446
                vpc.Status.ExtraExternalSubnets = vpc.Spec.ExtraExternalSubnets
×
1447
        } else {
×
1448
                vpc.Status.ExtraExternalSubnets = nil
×
1449
        }
×
1450

1451
        bytes, err := vpc.Status.Bytes()
×
1452
        if err != nil {
×
1453
                klog.Errorf("failed to get vpc bytes, %v", err)
×
1454
                return err
×
1455
        }
×
1456
        if _, err = c.config.KubeOvnClient.KubeovnV1().Vpcs().Patch(context.Background(),
×
1457
                vpc.Name, types.MergePatchType, bytes, metav1.PatchOptions{}, "status"); err != nil {
×
1458
                klog.Errorf("failed to patch vpc %s, %v", key, err)
×
1459
                return err
×
1460
        }
×
1461

1462
        return nil
×
1463
}
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2025 Coveralls, Inc