feat: add gateway-api support#299
Conversation
28079c5 to
f84c000
Compare
|
Dell Sonic does actually work, but you need credentials to pull from r.metal-stack.io. |
|
Sadly I got the following error: I had the following overrides |
|
|
@Sven-Ric Would you mind taking a look at the network changes? |
|
It seems like the kind node always ends up in the default kind network on a clean first run. The kind network is read from .env, which is written by env.sh. However the Makefile reads .env before env.sh is invoked and the kind node network falls back to default. Because .env is persistent the bug is masked on all subsequent runs. On initial run: # docker inspect metal-control-plane-control-plane
[
{
<SNIP>
"NetworkSettings": {
<SNIP>
"Networks": {
"kind": {
"IPAMConfig": null,
"Links": null,
"Aliases": null,
"DriverOpts": null,
"GwPriority": 0,
"NetworkID": "6530b19e41b397d41d37f6a38d6b1bbd74c9ba2b7478df95f6a6270cc84c4d0e",
"EndpointID": "6d56f5f0fa83330b85e0b0ebbd04175a93d8586c48492c9b545beb7eeecce015",
"Gateway": "172.18.0.1",
"IPAddress": "172.18.0.2",
"MacAddress": "12:98:42:c8:e4:ec",
"IPPrefixLen": 16,
"IPv6Gateway": "fc00:f853:ccd:e793::1",
"GlobalIPv6Address": "fc00:f853:ccd:e793::2",
"GlobalIPv6PrefixLen": 64,
"DNSNames": [
"metal-control-plane-control-plane",
"bd976835cec0"
]
}
}
},
"ImageManifestDescriptor": {
"mediaType": "application/vnd.docker.distribution.manifest.v2+json",
"digest": "sha256:21c46cf61fd45873f89e6a1bfcba4b7904dffa84c2bec88aeeca9a0409af4725",
"size": 743,
"platform": {
"architecture": "amd64",
"os": "linux"
}
}
}
]On all subsequent runs: # docker inspect metal-control-plane-control-plane
[
{
<SNIP>
"NetworkSettings": {
<SNIP>
"Networks": {
"mini_lab_internal": {
"IPAMConfig": null,
"Links": null,
"Aliases": null,
"DriverOpts": null,
"GwPriority": 0,
"NetworkID": "2734b8f942cae84d8693ecd43ab3bb9d5cd71905faf992fbfe5c3df17ddc376b",
"EndpointID": "62f8b2a6eb379bb65f13f6441a9249417fc9ce754218a29b699cd7511b393d29",
"Gateway": "172.42.0.1",
"IPAddress": "172.42.0.2",
"MacAddress": "66:e7:b9:9c:2e:39",
"IPPrefixLen": 16,
"IPv6Gateway": "",
"GlobalIPv6Address": "",
"GlobalIPv6PrefixLen": 0,
"DNSNames": [
"metal-control-plane-control-plane",
"5b12fbbedfdc"
]
}
}
},
"ImageManifestDescriptor": {
"mediaType": "application/vnd.docker.distribution.manifest.v2+json",
"digest": "sha256:21c46cf61fd45873f89e6a1bfcba4b7904dffa84c2bec88aeeca9a0409af4725",
"size": 743,
"platform": {
"architecture": "amd64",
"os": "linux"
}
}
}
] |
8075d54 to
ffc4120
Compare
Gerrit91
left a comment
There was a problem hiding this comment.
PR looks good to me. Thanks for the effort!
Would like to read the migration path somewhere. I guess for most operators it is sufficient to deploy a Gateway controller and then set metal_control_plane_gateway_dns: "{{ metal_control_plane_ingress_dns }} and when we remove the old metal_control_plane_ingress_dns then they need to replace the old variable in their deployment repository?
Still required for Dex, Thanos, Gardener, PowerDNS
Dex should not be used anymore, let's remove the role in another PR.
f80647f to
5819828
Compare
adeaa03 to
8da4fe3
Compare
|
|
e15f6b4 to
8aaaac4
Compare
To enable fixed IPs for the Gateway API, mini-lab needs a docker network that is not the docker default bridge. Create a dedicated `mini_lab_internal` network (172.42.0.0/16) and relocate everything off the old default network bridge (172.17.0.1 / 172.18.0.0). This shifts the control-plane ingress DNS from 172.17.0.1.nip.io to 172.42.0.1.nip.io. No Gateway API migration yet Signed-off-by: Benjamin Ritter <benjamin.ritter@x-cellent.com>
Add a metal-api server cert (api./v2. nip.io SANs) for the Gateway to terminate TLS with, add it to roll_certs.sh, and update the grpc cert host to the Gateway LoadBalancer IP. Signed-off-by: Benjamin Ritter <benjamin.ritter@x-cellent.com>
Add the Gateway API plumbing without wiring any application to it yet: Deploy cloud-provider-kind to provide LoadBalancer IPs. Add a `gateway` role deploying the Envoy Gateway controller, a GatewayClass, an EnvoyProxy pinned to the fixed LB IP 172.42.0.42, and the metal-control-plane Gateway. Register the role in the control-plane playbook and expose metal_control_plane_gateway_dns Signed-off-by: Benjamin Ritter <benjamin.ritter@x-cellent.com>
8aaaac4 to
aa1926b
Compare
Gerrit91
left a comment
There was a problem hiding this comment.
Looks really good now for me. Just some small remarks left, after this I would like to merge it.
I assume the ingress-controller is just there for Gardener exposal now? We can probably remove it in a subsequent PR and remove the ugly service status patching?
There was a problem hiding this comment.
Ingress-controller NGINX should be updated to Envoy Gateway? :)
| zitadel_endpoint: zitadel.{{ metal_control_plane_namespace }}.svc.cluster.local | ||
| zitadel_external_domain: auth.{{ metal_control_plane_ingress_dns }} | ||
| zitadel_ingress_dns: https://{{ zitadel_external_domain }}:4443 | ||
| zitadel_external_domain: zitadel.{{ metal_control_plane_gateway_dns }} |
There was a problem hiding this comment.
Why exactly this renaming? We thought that "auth" would be a bit less specific because it also works if we exchange the auth provider with something else that supports OIDC.
There was a problem hiding this comment.
Wanted to prevent confusion, as it is served via the same domain as the metalstack control plane api, while not being a metal-stack api component.
Thx, happy to hear that. Gardener, PowerDNS, Minio and Thanos come to mind. There is already a note in the docs, that some dependencies still require an ingress controller and replacing ingress nginx with a supported option is recommended. Going to look into what options are suitable for replacing ingress-nginx next. nginx follow up issue: #316 |
aa1926b to
4424515
Compare
Migrate zitadel, nsq, metal-api and metal-apiserver off ingress-nginx to Gateway API. Enable http/tcp routes, point their external URLs at the Gateway LoadBalancer (172.42.0.42 / gateway_dns). Signed-off-by: Benjamin Ritter <benjamin.ritter@x-cellent.com>
Signed-off-by: Benjamin Ritter <benjamin.ritter@x-cellent.com>
Signed-off-by: Benjamin Ritter <benjamin.ritter@x-cellent.com>
Signed-off-by: Benjamin Ritter <benjamin.ritter@x-cellent.com>
as we are not listening on the host we are free to use any port we like. So we switch to the default ports for https and http Signed-off-by: Benjamin Ritter <benjamin.ritter@x-cellent.com>
we need to put the CA data into an env var to later access metal-api. So we run cert generation on before calling the requested make target if certs are not generated yet. Signed-off-by: Benjamin Ritter <benjamin.ritter@x-cellent.com>
4424515 to
0bd111a
Compare
Description
Type: Loadbalancerservicesmini_lab_externaldocker networkWIPs
Link metal-roles pr branch to run ci in pull requestmetal-roles PR is mergedCloses: #297
Requires: metal-stack/helm-charts#156 and metal-stack/metal-roles#594
Tested configurations
Noteworthy
Used AI-Tools ✨