-
Notifications
You must be signed in to change notification settings - Fork 1.5k
OCPBUGS-112483: use api-int record for ignition host when using externally managed LB and DNS #10860
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
openshift-merge-bot
merged 2 commits into
openshift:main
from
shiftstack:ign-host-external-dns
Sep 18, 2026
Merged
OCPBUGS-112483: use api-int record for ignition host when using externally managed LB and DNS #10860
Changes from all commits
Commits
Show all changes
2 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,142 @@ | ||
| package machine | ||
|
|
||
| import ( | ||
| "net/url" | ||
| "testing" | ||
|
|
||
| "github.com/stretchr/testify/assert" | ||
| "github.com/stretchr/testify/require" | ||
| metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" | ||
|
|
||
| v1 "github.com/openshift/api/config/v1" | ||
| "github.com/openshift/installer/pkg/ipnet" | ||
| "github.com/openshift/installer/pkg/types" | ||
| "github.com/openshift/installer/pkg/types/openstack" | ||
| "github.com/openshift/installer/pkg/types/powervc" | ||
| ) | ||
|
|
||
| // hostFromPointerConfig is a helper that calls pointerIgnitionConfig and | ||
| // returns the host portion of the ignition merge URL. | ||
| func hostFromPointerConfig(t *testing.T, ic *types.InstallConfig, role string) string { | ||
| t.Helper() | ||
| cfg := pointerIgnitionConfig(ic, []byte("fake-ca"), role) | ||
| require.NotEmpty(t, cfg.Ignition.Config.Merge, "expected at least one merge entry") | ||
| src := cfg.Ignition.Config.Merge[0].Source | ||
| require.NotNil(t, src, "expected merge source to be set") | ||
| u, err := url.Parse(*src) | ||
| require.NoError(t, err, "unexpected error parsing ignition source URL") | ||
| return u.Host | ||
| } | ||
|
|
||
| // baseOpenStackIC returns a minimal OpenStack InstallConfig for use in tests. | ||
| func baseOpenStackIC(lbType v1.PlatformLoadBalancerType, dnsRecordsType v1.DNSRecordsType) *types.InstallConfig { | ||
| return &types.InstallConfig{ | ||
| ObjectMeta: metav1.ObjectMeta{Name: "test-cluster"}, | ||
| BaseDomain: "test-domain", | ||
| Networking: &types.Networking{ | ||
| ServiceNetwork: []ipnet.IPNet{*ipnet.MustParseCIDR("10.0.1.0/24")}, | ||
| }, | ||
| Platform: types.Platform{ | ||
| OpenStack: &openstack.Platform{ | ||
| APIVIPs: []string{"1.2.3.4"}, | ||
| LoadBalancer: &v1.OpenStackPlatformLoadBalancer{ | ||
| Type: lbType, | ||
| }, | ||
| DNSRecordsType: dnsRecordsType, | ||
| }, | ||
| }, | ||
| } | ||
| } | ||
|
|
||
| // basePowerVCIC returns a minimal PowerVC InstallConfig for use in tests. | ||
| func basePowerVCIC(lbType v1.PlatformLoadBalancerType) *types.InstallConfig { | ||
| p := &powervc.Platform{ | ||
| Cloud: "test-cloud", | ||
| APIVIPs: []string{"5.6.7.8"}, | ||
| LoadBalancer: &v1.OpenStackPlatformLoadBalancer{Type: lbType}, | ||
| } | ||
| return &types.InstallConfig{ | ||
| ObjectMeta: metav1.ObjectMeta{Name: "test-cluster"}, | ||
| BaseDomain: "test-domain", | ||
| Networking: &types.Networking{ | ||
| ServiceNetwork: []ipnet.IPNet{*ipnet.MustParseCIDR("10.0.1.0/24")}, | ||
| }, | ||
| Platform: types.Platform{PowerVC: p}, | ||
| } | ||
| } | ||
|
|
||
| // TestPointerIgnitionConfigOpenStack tests that the ignition host is set | ||
| // correctly for OpenStack depending on the LoadBalancer type and DNSRecordsType, | ||
| // for both the master and worker roles. | ||
| func TestPointerIgnitionConfigOpenStack(t *testing.T) { | ||
| cases := []struct { | ||
| name string | ||
| lbType v1.PlatformLoadBalancerType | ||
| dnsRecordsType v1.DNSRecordsType | ||
| expectedHost string | ||
| }{ | ||
| { | ||
| name: "user-managed LB with external DNS uses api-int FQDN", | ||
| lbType: v1.LoadBalancerTypeUserManaged, | ||
| dnsRecordsType: v1.DNSRecordsTypeExternal, | ||
| expectedHost: "api-int.test-cluster.test-domain:22623", | ||
| }, | ||
| { | ||
| name: "openshift-managed LB with internal DNS uses VIP", | ||
| lbType: v1.LoadBalancerTypeOpenShiftManagedDefault, | ||
| dnsRecordsType: v1.DNSRecordsTypeInternal, | ||
| expectedHost: "1.2.3.4:22623", | ||
| }, | ||
| { | ||
| name: "user-managed LB with internal DNS uses VIP", | ||
| lbType: v1.LoadBalancerTypeUserManaged, | ||
| dnsRecordsType: v1.DNSRecordsTypeInternal, | ||
| expectedHost: "1.2.3.4:22623", | ||
| }, | ||
| } | ||
|
|
||
| for _, role := range []string{"master", "worker"} { | ||
| for _, tc := range cases { | ||
| t.Run(role+"/"+tc.name, func(t *testing.T) { | ||
| ic := baseOpenStackIC(tc.lbType, tc.dnsRecordsType) | ||
| host := hostFromPointerConfig(t, ic, role) | ||
| assert.Equal(t, tc.expectedHost, host) | ||
| }) | ||
| } | ||
| } | ||
| } | ||
|
|
||
| // TestPointerIgnitionConfigPowerVC tests that the ignition host is always set | ||
| // to the API VIP for PowerVC, regardless of the LoadBalancer type, and for | ||
| // both the master and worker roles. | ||
| // PowerVC has no DNSRecordsType field, so the externally managed DNS | ||
| // condition that unlocks FQDN mode on OpenStack can never be met | ||
| // here. The VIP must always be used. | ||
| func TestPointerIgnitionConfigPowerVC(t *testing.T) { | ||
| userManaged := v1.LoadBalancerTypeUserManaged | ||
| openshiftManaged := v1.LoadBalancerTypeOpenShiftManagedDefault | ||
|
|
||
| cases := []struct { | ||
| name string | ||
| lbType v1.PlatformLoadBalancerType | ||
| }{ | ||
| { | ||
| name: "openshift-managed LB uses VIP", | ||
| lbType: openshiftManaged, | ||
| }, | ||
| { | ||
| name: "user-managed LB uses VIP", | ||
| lbType: userManaged, | ||
| }, | ||
| } | ||
|
|
||
| for _, role := range []string{"master", "worker"} { | ||
| for _, tc := range cases { | ||
| t.Run(role+"/"+tc.name, func(t *testing.T) { | ||
| ic := basePowerVCIC(tc.lbType) | ||
| host := hostFromPointerConfig(t, ic, role) | ||
| assert.Equal(t, "5.6.7.8:22623", host) | ||
| }) | ||
| } | ||
| } | ||
| } |
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'm unsure if the tests should live here, or in a new
node_test.gofile, or even in bothmaster_test.goandworker_test.go. Thoughts on this?There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Since the fix is applicable to both master and worker bringup paths, it makes sense to put the test in a common node_test.go where both paths are tested. Also the description of the PR says that this fix is also applicable to the vsphere platform. The current test has the install-config set only for platform openstack. We should add another test function for the vsphere platform again for both masters and workers.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
My bad. I meant the PowerVC platform and not the vsphere platform.