Skip to content

Commit e772f89

Browse files
fix(tmachine): reach the HA TLS gateway through its ClusterIP
Drop the port-forward restart removed by the ClusterIP change, resolve the Service DNS name covered by the server certificate to the ClusterIP, bound each authenticated API wait attempt, and collect diagnostics from every gateway Pod. Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
1 parent 1967155 commit e772f89

2 files changed

Lines changed: 16 additions & 8 deletions

File tree

‎tests/ansible/playbooks/openshell-k3s-ha-tls.yaml‎

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -58,10 +58,13 @@
5858
environment:
5959
KUBECONFIG: /etc/rancher/k3s/k3s.yaml
6060

61-
- name: Restart gateway forwarder after TLS upgrade
62-
ansible.builtin.systemd_service:
63-
name: openshell-k3s-port-forward.service
64-
state: restarted
61+
# The chart's server certificate covers the Service DNS name but not its
62+
# ClusterIP, and the node resolver cannot reach cluster DNS.
63+
- name: Resolve the gateway Service name to its ClusterIP
64+
ansible.builtin.lineinfile:
65+
path: /etc/hosts
66+
regexp: '\sopenshell\.openshell\.svc\.cluster\.local$'
67+
line: "{{ k3s_gateway_address.stdout.split(':')[0] }} openshell.openshell.svc.cluster.local"
6568

6669
- name: Read chart client TLS Secret
6770
ansible.builtin.command:
@@ -99,12 +102,12 @@
99102
apply:
100103
become: false
101104
vars:
102-
openshell_client_gateway_endpoint: https://localhost:17670
105+
openshell_client_gateway_endpoint: "https://openshell.openshell.svc.cluster.local:{{ k3s_gateway_address.stdout.split(':')[1] }}"
103106

104107
- name: Wait for authenticated gateway API
105108
become: false
106109
ansible.builtin.command:
107-
argv: [/usr/local/bin/openshell, sandbox, list, --output, json]
110+
argv: [timeout, 10s, /usr/local/bin/openshell, sandbox, list, --output, json]
108111
register: k3s_gateway_api
109112
until: k3s_gateway_api.rc == 0
110113
retries: 24

‎tests/ansible/roles/openshell_diagnostics/files/collect-k3s.sh‎

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -43,8 +43,13 @@ collect() {
4343
collect 'Endpoint readiness' /usr/local/bin/k3s kubectl --request-timeout=5s -n openshell get endpointslices \
4444
-o 'custom-columns=NAME:.metadata.name,PORTS:.ports,ADDRESSES:.endpoints[*].addresses,CONDITIONS:.endpoints[*].conditions'
4545
collect 'Gateway events' /usr/local/bin/k3s kubectl --request-timeout=5s -n openshell get events --sort-by=.lastTimestamp
46-
collect 'Gateway current logs' /usr/local/bin/k3s kubectl --request-timeout=5s -n openshell logs openshell-0 -c openshell-gateway --tail=300 --timestamps
47-
collect 'Gateway previous logs' /usr/local/bin/k3s kubectl --request-timeout=5s -n openshell logs openshell-0 -c openshell-gateway --previous --tail=300 --timestamps
46+
# Gateway Pods are named by a StatefulSet or a Deployment, depending on the installer.
47+
mapfile -t gateway_pods < <(timeout 10s /usr/local/bin/k3s kubectl --request-timeout=5s -n openshell get pods \
48+
--selector app.kubernetes.io/name=openshell,app.kubernetes.io/instance=openshell --output name 2>/dev/null)
49+
for pod in "${gateway_pods[@]}"; do
50+
collect "Gateway current logs ($pod)" /usr/local/bin/k3s kubectl --request-timeout=5s -n openshell logs "$pod" -c openshell-gateway --tail=300 --timestamps
51+
collect "Gateway previous logs ($pod)" /usr/local/bin/k3s kubectl --request-timeout=5s -n openshell logs "$pod" -c openshell-gateway --previous --tail=300 --timestamps
52+
done
4853
collect 'Memory' free -m
4954
collect 'Disk' df -h / /var/lib/rancher/k3s
5055
} | sed -E \

0 commit comments

Comments
 (0)