Skip to content

fix(controller): take Local targets from the nodes kube-proxy serves - #56

Open
lexfrei wants to merge 1 commit into
perf/watch-cluster-changesfrom
fix/local-targets-from-slices
Open

lexfrei wants to merge 1 commit into
perf/watch-cluster-changesfrom
fix/local-targets-from-slices

Conversation

@lexfrei

@lexfrei lexfrei commented Sep 29, 2026

Copy link
Copy Markdown
Collaborator

Local services now take their targets from their EndpointSlices, the same way services without a selector already did. Before, a service with a selector used the nodes of the pods it matched. So a node with a pod that was not ready yet stayed a target while kube-proxy had nothing there to send traffic to. A cordoned or not-ready node running a pod always stayed a target too, and now its endpoints decide.

A node is a target when kube-proxy serves Local traffic from it. That means a ready endpoint on the node, or a terminating endpoint that still serves, which kube-proxy falls back to while the node has no ready one. Missing conditions are read the way kube-proxy reads them: ready and serving default to true, terminating to false. See topology.go and endpointslicecache.go.

The endpoint slice trigger from #49 uses the same filter now. Its pod-based mode is gone, and robotlb does not read pods anymore, so the chart's default role no longer grants access to them. A custom serviceAccount.permissions list is not touched.

Stacked on #49.

Closes #48

A Local service with a selector took its targets from the pods the
selector matched. That kept nodes where kube-proxy had no endpoint to
send traffic to, such as the node of a pod that is not ready yet, and
so nodes that fail the balancer's health check. A cordoned or
not-ready node running a matching pod stayed a target too, unlike
under the Cluster policy, with nothing saying whether that was
intended.

Every Local service now takes its targets from its EndpointSlices, the
path already used for services without a selector. A node is a target
when kube-proxy serves Local traffic from it: it has a ready endpoint,
or a terminating endpoint that still serves, which kube-proxy falls
back to while the node has no ready one. Missing conditions are read
the way kube-proxy reads them.

Targets and the slice trigger share this filter, so the trigger no
longer needs a separate pod-based mode. robotlb no longer reads pods
at all, and the chart's default role drops its access to them.

Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <f@lex.la>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant