Kubernetes controller that watches a remote cluster for node changes and updates service endpoints
280
https://github.com/traum-ferienwohnungen/barrelman
Watches a remote clusters nodes and services for changes and updates local clusters services and endpoints accordingly.
Developed and used to keep service reachable via in-cluser URLs from multiple clusters. This is "hacked" by creating dummy services in cluster A pointing to node IPs and ports of cluster B.
Currently the authentication towards the remote cluster is tightened to Google Kubernetes Engine clusters.
Barrelman consists of two different controller routines, watching for different events in remote-cluster.
This only handles service with the label tfw.io/barrelman set to "true" or "managed-resource"
(see ServiceController for the latter).
Watch for changes of service objects in local-cluster:
targetPort of serviceWatch for changes of nodes in remote-cluster:
ServiceController operates on services in remote-cluster if they are not within a ignored namespace
(--ignore-namespace, kube-system is ignored by default) and not ignored via annotation
(tfw.io/barrelman: ignore).
Services in local-cluster are only updated/deleted if they are labeled with
(tfw.io/barrelman: managed-resource). Namespaces created by barrelman are never removed.
Watch for changes of service objects in local-cluster:
Watch for changes of services objects in remote-cluster:
Imaging there is cluster X and Y (Nodes Xn and Yn) with barrelman running as Xb and Yb.
Local cluster may be specified via local-kubeconfig and local-context. If omitted, in-cluster credentials will
be used (where possible).
Remote cluster must be defined via remote-project, remote-zone and remote-cluster-name. Cluster credentials and
config (API Host etc.) will then be auto generated via a Google APIs using the service account provided via the
environment Variable GOOGLE_APPLICATION_CREDENTIALS.
barrelman -v 3 \
-local-kubeconfig ~/.kube/config \
-local-context "gke_gcp-project_region-and-zone_local-cluster-name" \
-remote-cluster-name remote-cluster-name \
-resync-period 1m
See rbac.yaml
Needs service account with "Kubernetes Engine Viewer" IAM permission (to read node and service details).
To create a service account, use:
PROJECT="gcp-project"
gcloud --project="$PROJECT" iam service-accounts create barrelman --display-name barrelman
# Grant Kubernetes Engine Viewer permission
gcloud projects add-iam-policy-binding $PROJECT \
--member serviceAccount:barrelman@${PROJECT}.iam.gserviceaccount.com --role "roles/container.viewer"
# Create a service account key (to be used in CI/CD)
gcloud iam service-accounts keys create service-account.json \
--iam-account=barrelman@${PROJECT}.iam.gserviceaccount.com
# Base64 encode the service account, store the output in GitLab CI variable REMOTE_SERVICE_ACCOUNT
base64 -w0 < service-account.json
#!/bin/bash
STAGED_GO_FILES=$(git diff --cached --name-only | grep ".go$")
if [[ "$STAGED_GO_FILES" = "" ]]; then
exit 0
fi
exec golangci-lint run --fix
Content type
Image
Digest
Size
16.6 MB
Last updated
almost 7 years ago
docker pull traumfewo/barrelman:v0.2.0