Commits on Source 22

  • Igor's avatar
    Recover the instance zone for stop, start, and inspect in bulk mode · 30d3d79c
    Igor authored
    deleteInstance already recovers from the empty-zone state a failed
    bulkInsert leaves behind, but stop, start, and instance lookups still
    called the API with an empty zone and failed with "Invalid value for
    field 'zone': ''" (400). The runner hits this when draining a machine
    whose create never resolved a zone.
    
    Factor the recovery into ensureZone and use it in all four paths. As
    with delete, a machine that was never placed yields a not-found error
    so callers treat it as gone.
    30d3d79c
  • Igor's avatar
    Trim the ensureZone comment · e6af6ab8
    Igor authored
    e6af6ab8
  • Igor's avatar
    Write the recovered zone back to the driver · 60754e7f
    Igor authored
    Each driver method builds a fresh ComputeUtil, so an in-memory recovery
    lasted one call: a single stop discovered the zone three times (inspect,
    stop, inspect). Writing it back to ResolvedZone makes one AggregatedList
    serve the whole invocation, and persists to the machine config when
    libmachine saves the host.
    60754e7f
  • Igor's avatar
    Skip the pre-create existence check in bulk mode · 77226c9c
    Igor authored
    No zone is resolved before placement, so the check never found
    anything in bulk mode: it always got a 400 on the empty zone and
    passed. With zone recovery it would instead cost an AggregatedList on
    every create. UseExisting keeps the lookup.
    77226c9c
  • Igor's avatar
    Propagate zone-lookup failures instead of synthesizing not-found · 4a9f3076
    Igor authored
    Only a successful AggregatedList that finds no instance means the
    instance is absent. A failed lookup (403, 5xx, transport error) said
    nothing, yet was also turned into a synthetic 404, letting callers reap
    local state while the VM may still be running. Lookup failures now
    propagate, for delete as well.
    
    The pre-create existence check also returns for bulk-mode retries that
    already carry a persisted ResolvedZone, keeping duplicate protection
    via a cheap zonal lookup. Only the no-zone first attempt skips it.
    
    The stop/start/inspect recovery tests now assert the exact method and
    path, so a wrong operation against the right zone no longer passes.
    4a9f3076
  • Igor's avatar
    Route ip() through zone recovery and drop a dead condition · 08b4823e
    Igor authored
    GetIP was the remaining zone consumer reachable with an unresolved
    zone: called before any recovered operation, it still hit the raw
    empty-zone 400. deleteDisk needs nothing: Remove reuses the ComputeUtil
    whose zone deleteInstance already recovered.
    
    The UseExisting clause in the pre-create gate was dead: UseExisting and
    BulkInsert are mutually exclusive at flag parsing, so effectiveZone is
    never empty when UseExisting is set.
    08b4823e
  • Igor's avatar
    Pass the ensureZone error through in ip() · 58918c17
    Igor authored
    unwrapGoogleError flattened the synthetic 404 into a plain error,
    which defeated callers' isNotFound checks.
    58918c17
  • Igor's avatar
    Return lookup failures from GetState instead of state.None · c454b697
    Igor authored
    GetState swallowed the instance and disk lookup errors, so a transient
    API failure (403, 5xx, transport) reported an existing machine as
    absent, and state.None is what tells callers to reap local state. Only
    a genuine not-found proceeds to the disk check or reports absence now.
    c454b697
  • Igor's avatar
    Merge branch 'fix/bulk-insert-zone-recovery-stop-start' into 'main' · 24981811
    Igor authored
    Recover the instance zone for stop, start, and inspect in bulk mode
    
    See merge request !187
    
    Merged-by: Igor's avatarIgor <iwiedler@gitlab.com>
    Approved-by: Kam Kyrala's avatarKam Kyrala <kkyrala@gitlab.com>
    Approved-by: default avatarTomasz Maczukin <tomasz@maczukin.pl>
    Reviewed-by: default avatarGitLab Duo <gitlab-duo@gitlab.com>
    24981811
  • Igor's avatar
    Add update-labels command backed by a LabelUpdater driver interface · 6009a76b
    Igor authored
    Managers need to refresh a liveness label on the instances they track
    so an external reaper can tell orphaned VMs from tracked ones
    (production-engineering#29652). The google driver merges labels into
    the instance via SetLabels with the current fingerprint. Drivers that
    don't implement LabelUpdater report label updates as unsupported.
    6009a76b
  • Igor's avatar
    Add merge and RPC tests for update-labels · e28be310
    Igor authored
    Review feedback: the label-merge and fingerprint handling in the google
    driver and the RPC delegation had no coverage, only the command layer.
    e28be310
  • Igor's avatar
    Fix import grouping in compute_util_test · b7f79c4f
    Igor authored
    b7f79c4f
  • Igor's avatar
    Trim comments to the non-obvious · f368c726
    Igor authored
    f368c726
  • Igor's avatar
    Degrade to ErrLabelsNotSupported on plugins without UpdateLabels · 3d2a2bd0
    Igor authored
    An older plugin passes the API version handshake and then fails the
    label call with a raw rpc method-lookup error. Map that to the same
    error a non-implementing driver returns. Bumping the RPC API version
    instead would reject every external driver plugin built against v1,
    which is disproportionate for an optional feature.
    3d2a2bd0
  • Igor's avatar
    Trim the fallback comment · 02cff922
    Igor authored
    02cff922
  • Igor's avatar
    Require exactly one machine name for update-labels · 559e53be
    Igor authored
    Review feedback: zero arguments previously resolved the docker-machine
    default host, which is meaningless for label updates. Also clarify the
    invalid-label error message.
    559e53be
  • Igor's avatar
    Merge branch 'update-labels' into 'main' · 69c878b8
    Igor authored
    Add update-labels command backed by a LabelUpdater driver interface
    
    See merge request !190
    
    Merged-by: Igor's avatarIgor <iwiedler@gitlab.com>
    Approved-by: default avatarTomasz Maczukin <tomasz@maczukin.pl>
    Reviewed-by: default avatarTomasz Maczukin <tomasz@maczukin.pl>
    Reviewed-by: default avatarGitLab Duo <gitlab-duo@gitlab.com>
    69c878b8
  • Igor's avatar
    Add a separate COS readiness URL egress check · befcc21c
    Igor authored
    Split the Google COS readiness gate into two independent opt-ins. The
    existing --google-cos-docker-network-readiness-gate now only waits for
    cloud-init. A new --google-cos-docker-network-readiness-url runs the
    container egress probe against the given URL, and only when it is set.
    
    The previous probe fetched the GCE metadata server on :80 from a probe
    container. On a correctly-firewalled worker the DOCKER-USER rule drops
    container traffic to the metadata server, so the probe could never pass
    there and every machine creation failed. Fetching an operator-supplied
    URL exercises the same bridge NAT/FORWARD/MASQUERADE path against a
    destination the worker firewall permits. Success means any HTTP response
    came back; a redirect or an error status still proves egress works.
    
    The URL is validated driver-side (http/https, host present, no shell
    metacharacters) before it reaches the worker shell command.
    befcc21c
  • Igor's avatar
    Quote the readiness URL instead of blocklisting characters · 47c9c408
    Igor authored
    The URL reached the worker shell interpolated unquoted, guarded by a
    character blocklist. The blocklist rejected legitimate URLs (query
    strings) and was the wrong tool for injection safety.
    
    Pass the URL as a positional argument to the inner sh -c and single-quote
    it (' -> '\''), so any value reaches wget as one literal word. The
    driver-side check keeps only the http/https scheme and host validation
    for a fast failure at flag time.
    
    TestShellQuoteSurvivesTwoShellLayers runs hostile inputs (embedded
    quotes, command substitution, backticks, query strings) through both
    shell layers and asserts the URL arrives verbatim with no side effect.
    47c9c408
  • Igor's avatar
    Bump version to 0.16.2-gitlab.54 · 5c9758d5
    Igor authored
    5c9758d5
  • Igor's avatar
    Merge branch 'iwiedler/cos-readiness-url' into 'main' · 22435d0a
    Igor authored
    Add a separate COS readiness URL egress check
    
    See merge request !191
    
    Merged-by: Igor's avatarIgor <iwiedler@gitlab.com>
    Approved-by: Kam Kyrala's avatarKam Kyrala <kkyrala@gitlab.com>
    Reviewed-by: default avatarGitLab Duo <gitlab-duo@gitlab.com>
    22435d0a
  • Igor's avatar
    Merge branch 'bump-version-0.16.2-gitlab.54' into 'main' · 93f6fba1
    Igor authored
    Bump version to 0.16.2-gitlab.54
    
    See merge request !192
    
    Merged-by: Igor's avatarIgor <iwiedler@gitlab.com>
    Approved-by: default avatarAxel von Bertoldi <avonbertoldi@gitlab.com>
    93f6fba1
Loading
Loading