examples/demo: fix two real bugs this exact demo just hit live
1. Renamed every object this demo creates (TerdutServer, Postgres
Secret/Deployment/Service) from terdut-demo[-postgres] to
terdut-operator-demo[-postgres]. The user applied this kit into the
already-live "terdut-demo" namespace -- the real operator exercise
from earlier in this repo's own history -- and this demo's own
TerdutServer/Postgres objects shared that exact name. The TerdutServer
apply was rejected outright (DatabaseSpec's own CEL rule: adding dsn
while the live object already had postgresClusterRef violates "exactly
one of" and the API server refused it), and the real Postgres Service
was never touched (confirmed live: still Zalando's own spilo selector,
endpoint still the real StatefulSet pod) -- but the Postgres Secret and
Deployment, having no such protection, were created as brand new,
extra, crash-looping objects sitting right next to the real ones.
Prefixing every name this demo creates means a repeat of this exact
mistake no longer collides with anything, documented directly in
README.md now.
2. The actual crash itself, independent of (1): capabilities.drop: ["ALL"]
(added responding to a PodSecurity "restricted" warning) took
CAP_CHOWN/CAP_FOWNER away from the root user postgres:17-alpine's own
entrypoint needs to chown/chmod the data directory before it drops
privileges itself -- confirmed in a real crashed pod's logs: `chmod:
/var/run/postgresql: Operation not permitted`. kubectl apply
--dry-run=server, which is as far as this got verified before, only
checks admission policy; it was never actually booted. Removed the
capability drop and verified for real this time: applied just
00-postgres.yaml alone into a disposable namespace, waited for the pod
to go Ready, read its logs ("database system is ready to accept
connections"), then deleted that namespace.
This commit is contained in:
+15
-4
@@ -18,6 +18,17 @@ directory. Throw the whole namespace away when you're done.
|
||||
throwaway resources in. A `kind` cluster is the easy choice.
|
||||
- `kubectl`, `jq`, `curl` on your path.
|
||||
|
||||
**Apply this into a namespace of its own.** Every object name in this
|
||||
directory is prefixed `terdut-operator-demo` specifically so applying it
|
||||
by mistake into some other namespace that already has unrelated objects
|
||||
doesn't collide with them -- but that only helps if this directory's own
|
||||
objects don't collide with *each other* across two applies. Applying it
|
||||
twice into two different namespaces is fine; applying it a second time
|
||||
into a namespace that already has something else named `terdut-demo` (a
|
||||
real install from following `terdut-operator`'s own repo along, say) is
|
||||
exactly the mistake this prefix exists to avoid, and it only works if you
|
||||
don't override these names yourself.
|
||||
|
||||
## Apply it
|
||||
|
||||
```sh
|
||||
@@ -40,10 +51,10 @@ kubectl get terdutservers,terdutteams,terdutescalationrules,terdutdeadmanswitche
|
||||
|
||||
The operator's own Deployment template now carries a `wait-for-postgres`
|
||||
init container (same fix as `charts/terdut-server`'s chart as of v0.33.2),
|
||||
so `terdut-demo`'s pod should come up clean even against this brand-new
|
||||
so `terdut-operator-demo`'s pod should come up clean even against this brand-new
|
||||
Postgres doing its very first boot — no `CrashLoopBackOff` expected here.
|
||||
|
||||
Once `terdut-demo`'s own `Ready` condition is `True`, everything downstream
|
||||
Once `terdut-operator-demo`'s own `Ready` condition is `True`, everything downstream
|
||||
of it should settle within a reconcile interval or two.
|
||||
|
||||
## See the web UI
|
||||
@@ -53,7 +64,7 @@ The operator doesn't create any external exposure yet
|
||||
— `spec.networking.hostname` is accepted but nothing acts on it), so:
|
||||
|
||||
```sh
|
||||
kubectl -n terdut-operator-demo port-forward svc/terdut-demo 8080:8080
|
||||
kubectl -n terdut-operator-demo port-forward svc/terdut-operator-demo 8080:8080
|
||||
```
|
||||
|
||||
and open http://localhost:8080.
|
||||
@@ -72,7 +83,7 @@ kubectl get deploy -A -l control-plane=controller-manager
|
||||
|
||||
# The Secret holding the operator's own admin token for this TerdutServer
|
||||
# (cross-namespace from terdut-operator-demo, per DESIGN.md §7):
|
||||
secretname=$(kubectl -n terdut-operator-demo get terdutserver terdut-demo \
|
||||
secretname=$(kubectl -n terdut-operator-demo get terdutserver terdut-operator-demo \
|
||||
-o jsonpath='{.status.credentialsSecretRef.name}')
|
||||
token=$(kubectl -n <operator-namespace-from-above> get secret "$secretname" \
|
||||
-o jsonpath='{.data.token}' | base64 -d)
|
||||
|
||||
Reference in New Issue
Block a user