feat(discovery): expose read-only cluster inventory - #281
efegokdemir wants to merge 8 commits into
Conversation
Add a read-only library entry point that consumes an existing NIC Configuration Daemon and NicDevice resources without mutating cluster state. Return a sentinel when the daemon is absent and document the read-only RBAC contract. Fixes NVIDIA#62 Signed-off-by: Efe Gökdemir <efe@rexcode.co.uk>
|
Signed-off-by: Efe Gökdemir <efe@rexcode.co.uk>
|
Updated the read-only discovery path to address the review findings: it now locates the existing daemon across namespaces, scopes inventory to Ready daemon nodes, derives a selector for a single group, returns Validation: |
Signed-off-by: Efe Gökdemir <efe@rexcode.co.uk>
|
Follow-up update on the latest review: read-only discovery now rejects incomplete inventories instead of silently omitting ready daemon nodes, prefers a non-bootstrap operator namespace when both exist, verifies derived selectors do not match outside nodes, and documents the required cluster-wide pod/NicDevice list permissions. Validation: |
Signed-off-by: Efe Gökdemir <efe@rexcode.co.uk>
|
Updated at bcc3a22: daemon lookup now uses namespace-scoped reads with Network Operator preference, preserves ready-node/NicDevice completeness filtering, and validates selectors against all node labels. Documentation and regression coverage were updated. Local validation passed: go test ./... -count=1; go test ./... -race -count=1; go vet ./...; go build ./...; make lint; python3 scripts/check-docs.py --binary build/l8k; git diff --check. |
Signed-off-by: Efe Gökdemir <efe@rexcode.co.uk>
|
Verified and fixed the selector finding in Added regressions for a non-unique first label followed by a unique label and for the no-safe-candidate case. Validation: |
Signed-off-by: Efe Gökdemir <efe@rexcode.co.uk>
|
Addressed the remaining namespace/readiness findings in Added regressions for custom namespaces and unready-preferred fallback. Validation: |
Signed-off-by: Efe Gökdemir <efe@rexcode.co.uk>
Signed-off-by: Efe Gökdemir <efe@rexcode.co.uk>
|
Addressed the three latest findings in
Validation: |
Summary
networkoperatorplugin.DiscoverReadOnlyfor clusters with an existing NIC Configuration DaemonErrNotInstalledwhen no daemon pod is presentNicDeviceresources without bootstrap, label patches, or cleanupTesting
go test ./pkg/networkoperatorplugin/... -count=1go test ./... -race -count=1go vet ./...go build ./...make testmake lintpython3 scripts/check-docs.py --binary build/l8kgit diff --checkFixes #62