Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions charts/fleet-crd/templates/crds.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6388,6 +6388,14 @@ spec:
sha256sum:
description: SHA256Sum of the Content field
type: string
status:
description: ContentStatus defines the observed state of Content
properties:
referenceCount:
description: ReferenceCount is the number of BundleDeployments that
currently reference this Content resource.
type: integer
type: object
type: object
served: true
storage: true
Expand Down
4 changes: 4 additions & 0 deletions integrationtests/gitjob/controller/suite_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ import (
appsv1 "k8s.io/api/apps/v1"
corev1 "k8s.io/api/core/v1"

"github.com/rancher/fleet/internal/cmd/controller/gitops"
"github.com/rancher/fleet/internal/cmd/controller/gitops/reconciler"
ctrlreconciler "github.com/rancher/fleet/internal/cmd/controller/reconciler"
"github.com/rancher/fleet/internal/cmd/controller/target"
Expand Down Expand Up @@ -89,6 +90,9 @@ var _ = BeforeSuite(func() {
})
Expect(err).ToNot(HaveOccurred())

Expect(gitops.AddRepoNameLabelIndexer(ctx, mgr)).ToNot(HaveOccurred())
Expect(gitops.AddImageScanGitRepoIndexer(ctx, mgr)).ToNot(HaveOccurred())

ctlr := gomock.NewController(GinkgoT())

// redirect logs to a buffer that we can read in the tests
Expand Down
73 changes: 11 additions & 62 deletions internal/cmd/controller/finalize/finalize.go
Original file line number Diff line number Diff line change
Expand Up @@ -6,15 +6,11 @@ import (
"strings"

"github.com/rancher/fleet/pkg/apis/fleet.cattle.io/v1alpha1"
"github.com/rancher/wrangler/v3/pkg/kv"

corev1 "k8s.io/api/core/v1"
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
"k8s.io/apimachinery/pkg/types"
"k8s.io/client-go/util/retry"
"sigs.k8s.io/controller-runtime/pkg/client"
"sigs.k8s.io/controller-runtime/pkg/controller/controllerutil"
"sigs.k8s.io/controller-runtime/pkg/log"
)

const (
Expand Down Expand Up @@ -66,64 +62,6 @@ func PurgeBundles(ctx context.Context, c client.Client, gitrepo types.Namespaced
return nil
}

// PurgeContent tries to delete the content resource related with the given bundle deployment.
func PurgeContent(ctx context.Context, c client.Client, name, deplID string) error {
contentID, _ := kv.Split(deplID, ":")
content := &v1alpha1.Content{}
if err := c.Get(ctx, types.NamespacedName{Name: contentID}, content); err != nil {
return client.IgnoreNotFound(err)
}

logger := log.FromContext(ctx).WithName("purge-content").WithValues("contentID", contentID, "finalizerName", name)

nn := types.NamespacedName{Name: content.Name}
if controllerutil.ContainsFinalizer(content, name) {
err := retry.RetryOnConflict(retry.DefaultRetry, func() error {
if err := c.Get(ctx, nn, content); err != nil {
return client.IgnoreNotFound(err)
}

controllerutil.RemoveFinalizer(content, name)

return c.Update(ctx, content)
})
if err != nil {
return err
}

logger.V(1).Info("Removed finalizer from content resource")
}

if len(content.Finalizers) == 0 {
if err := c.Delete(ctx, content); err != nil {
return err
}
logger.V(1).Info("Deleted content resource")
}

return nil
}

// PurgeImageScans deletes all ImageScan resources related with the given GitRepo namespaces name.
func PurgeImageScans(ctx context.Context, c client.Client, gitrepo types.NamespacedName) error {
images := &v1alpha1.ImageScanList{}
err := c.List(ctx, images, client.InNamespace(gitrepo.Namespace))
if err != nil {
return err
}

for _, image := range images.Items {
if image.Spec.GitRepoName == gitrepo.Name {
err := c.Delete(ctx, &image)
if err != nil {
return err
}
}

}
return nil
}

// PurgeNamespace deletes the given namespace if deleteNamespace is set to true.
// It ignores the following namespaces, that are considered as default by fleet or kubernetes:
// fleet-local, cattle-fleet-system, fleet-default, cattle-fleet-clusters-system, default
Expand Down Expand Up @@ -168,3 +106,14 @@ func EnsureFinalizer(ctx context.Context, c client.Client, obj client.Object, fi
controllerutil.AddFinalizer(obj, finalizer)
return c.Update(ctx, obj)
}

func PurgeTargetNamespaceIfNeeded(ctx context.Context, c client.Client, gitrepo *v1alpha1.GitRepo) error {
deleteNamespace := gitrepo.Spec.DeleteNamespace
namespace := gitrepo.Spec.TargetNamespace

if gitrepo.Spec.KeepResources {
deleteNamespace = false
}

return PurgeNamespace(ctx, c, deleteNamespace, namespace)
}
51 changes: 51 additions & 0 deletions internal/cmd/controller/gitops/operator.go
Original file line number Diff line number Diff line change
Expand Up @@ -20,11 +20,13 @@ import (
"sigs.k8s.io/controller-runtime/pkg/client"
clog "sigs.k8s.io/controller-runtime/pkg/log"
"sigs.k8s.io/controller-runtime/pkg/log/zap"
"sigs.k8s.io/controller-runtime/pkg/manager"
metricsserver "sigs.k8s.io/controller-runtime/pkg/metrics/server"

command "github.com/rancher/fleet/internal/cmd"
"github.com/rancher/fleet/internal/cmd/controller/gitops/reconciler"
fcreconciler "github.com/rancher/fleet/internal/cmd/controller/reconciler"
"github.com/rancher/fleet/internal/config"
"github.com/rancher/fleet/internal/metrics"
"github.com/rancher/fleet/internal/ssh"
fleet "github.com/rancher/fleet/pkg/apis/fleet.cattle.io/v1alpha1"
Expand Down Expand Up @@ -140,6 +142,18 @@ func (g *GitOperator) Run(cmd *cobra.Command, args []string) error {

kh := ssh.KnownHosts{EnforceHostKeyChecks: !g.SkipHostKeyChecks}

// Add an indexer for the Gitrepo name label as that will make accesses in the cache
// faster
if err := AddRepoNameLabelIndexer(ctx, mgr); err != nil {
return err
}

// Add an indexer for the GitRepo name field in ImageScans as that will make accesses in the cache
// faster
if err := AddImageScanGitRepoIndexer(ctx, mgr); err != nil {
return err
}

gitJobReconciler := &reconciler.GitJobReconciler{
Client: mgr.GetClient(),
Scheme: mgr.GetScheme(),
Expand Down Expand Up @@ -245,3 +259,40 @@ func startWebhook(ctx context.Context, namespace string, addr string, client cli

return nil
}

func AddRepoNameLabelIndexer(ctx context.Context, mgr manager.Manager) error {
return mgr.GetFieldIndexer().IndexField(
ctx,
&fleet.Bundle{},
config.RepoNameIndex,
func(obj client.Object) []string {
content, ok := obj.(*fleet.Bundle)
if !ok {
return nil
}
if name, exists := content.Labels[fleet.RepoLabel]; exists {
return []string{name}
}

return nil
},
)
}

func AddImageScanGitRepoIndexer(ctx context.Context, mgr manager.Manager) error {
return mgr.GetFieldIndexer().IndexField(
ctx,
&fleet.ImageScan{},
config.ImageScanGitRepoIndex,
func(obj client.Object) []string {
content, ok := obj.(*fleet.ImageScan)
if !ok {
return nil
}
if content.Spec.GitRepoName == "" {
return nil
}
return []string{content.Spec.GitRepoName}
},
)
}
114 changes: 101 additions & 13 deletions internal/cmd/controller/gitops/reconciler/gitjob_controller.go
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@ import (
"github.com/rancher/fleet/internal/cmd/controller/imagescan"
ctrlquartz "github.com/rancher/fleet/internal/cmd/controller/quartz"
"github.com/rancher/fleet/internal/cmd/controller/reconciler"
"github.com/rancher/fleet/internal/config"
"github.com/rancher/fleet/internal/metrics"
v1alpha1 "github.com/rancher/fleet/pkg/apis/fleet.cattle.io/v1alpha1"
"github.com/rancher/fleet/pkg/durations"
Expand All @@ -29,6 +30,7 @@ import (
batchv1 "k8s.io/api/batch/v1"
corev1 "k8s.io/api/core/v1"
apierrors "k8s.io/apimachinery/pkg/api/errors"
"k8s.io/apimachinery/pkg/api/meta"
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
"k8s.io/apimachinery/pkg/apis/meta/v1/unstructured"
"k8s.io/apimachinery/pkg/labels"
Expand Down Expand Up @@ -56,6 +58,10 @@ const (
// make sure Prometheus scrapes them.
ShortLivedMetricsTTL = 120 * time.Second
gitJobPollingJitterPercent = 10

// period after which the GitRepo reconciler is re-scheduled,
// in order to wait for the dependent resources cleanup to finish
requeueAfterResourceCleanup = 2 * time.Second
)

var (
Expand Down Expand Up @@ -179,9 +185,7 @@ func (r *GitJobReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ctr

if !gitrepo.DeletionTimestamp.IsZero() {
if controllerutil.ContainsFinalizer(gitrepo, finalize.GitRepoFinalizer) {
if err := r.cleanupGitRepo(ctx, logger, gitrepo); err != nil {
return ctrl.Result{}, err
}
return r.handleDelete(ctx, logger, gitrepo)
}

return ctrl.Result{}, nil
Expand Down Expand Up @@ -357,25 +361,50 @@ func (r *GitJobReconciler) deletePreviousJob(ctx context.Context, logger logr.Lo
return r.Delete(ctx, &job)
}

func (r *GitJobReconciler) cleanupGitRepo(ctx context.Context, logger logr.Logger, gitrepo *v1alpha1.GitRepo) error {
func (r *GitJobReconciler) handleDelete(ctx context.Context, logger logr.Logger, gitrepo *v1alpha1.GitRepo) (ctrl.Result, error) {
logger.Info("Gitrepo deleted, deleting bundle, image scans")

metrics.GitRepoCollector.Delete(gitrepo.Name, gitrepo.Namespace)
_ = r.deletePollingJob(*gitrepo)

nsName := types.NamespacedName{Name: gitrepo.Name, Namespace: gitrepo.Namespace}
if err := finalize.PurgeBundles(ctx, r.Client, nsName, v1alpha1.RepoLabel); err != nil {
return err
if !controllerutil.ContainsFinalizer(gitrepo, finalize.GitRepoFinalizer) {
return ctrl.Result{}, nil
}

bundles, err := r.listBundlesForGitrepo(ctx, gitrepo)
if err != nil {
return ctrl.Result{}, err
}

// Bundle deletion happens asynchronously: mark them for deletion and requeue
// This ensures the Gitrepo is kept around until all its Bundles are completely deleted.
if len(bundles.Items) > 0 {
logger.V(1).Info("GitRepo deleted, purging bundles")
return ctrl.Result{RequeueAfter: requeueAfterResourceCleanup}, batchDeleteDependentResources(ctx, r.Client, bundles)
}

// remove the job scheduled by imagescan, if any
_ = r.Scheduler.DeleteJob(imagescan.GitCommitKey(gitrepo.Namespace, gitrepo.Name))

if err := finalize.PurgeImageScans(ctx, r.Client, nsName); err != nil {
return err
images, err := r.listImageScansForGitrepo(ctx, gitrepo)
if err != nil {
return ctrl.Result{}, err
}

if len(images.Items) > 0 {
logger.V(1).Info("GitRepo deleted, purging imagescans")
return ctrl.Result{RequeueAfter: requeueAfterResourceCleanup}, batchDeleteDependentResources(ctx, r.Client, images)
}

// Delete the target namespace if DeleteNamespace is true
if err := finalize.PurgeTargetNamespaceIfNeeded(ctx, r.Client, gitrepo); err != nil {
return ctrl.Result{}, err
}

err := retry.RetryOnConflict(retry.DefaultRetry, func() error {
metrics.GitRepoCollector.Delete(gitrepo.Name, gitrepo.Namespace)

// we don't have pending Bundles nor ImageScans, we can remove the finalizer
nsName := types.NamespacedName{Name: gitrepo.Name, Namespace: gitrepo.Namespace}
err = retry.RetryOnConflict(retry.DefaultRetry, func() error {
if err := r.Get(ctx, nsName, gitrepo); err != nil {
return err
}
Expand All @@ -386,10 +415,10 @@ func (r *GitJobReconciler) cleanupGitRepo(ctx context.Context, logger logr.Logge
})

if client.IgnoreNotFound(err) != nil {
return err
return ctrl.Result{}, err
}

return nil
return ctrl.Result{}, nil
}

// shouldCreateJob checks if the conditions to create a new job are met.
Expand Down Expand Up @@ -600,6 +629,41 @@ func (r *GitJobReconciler) managePollingJob(logger logr.Logger, gitrepo v1alpha1
return jobUpdatedOrCreated, nil
}

func (r *GitJobReconciler) listBundlesForGitrepo(ctx context.Context, gitrepo *v1alpha1.GitRepo) (*v1alpha1.BundleList, error) {
list := &v1alpha1.BundleList{}
// if err := r.List(ctx, list,
// client.MatchingFields{
// "metadata.labels.gitrepo-name+namespace": GetNamespaceAndNameID(gitrepo.Namespace, gitrepo.Name),
// },
// ); err != nil {
// return nil, err
// }

err := r.List(ctx, list, client.MatchingLabels{v1alpha1.RepoLabel: gitrepo.Name}, client.InNamespace(gitrepo.Namespace))
if err != nil {
return nil, err
}
return list, nil
}

func (r *GitJobReconciler) listImageScansForGitrepo(ctx context.Context, gitrepo *v1alpha1.GitRepo) (*v1alpha1.ImageScanList, error) {
list := &v1alpha1.ImageScanList{}

if err := r.List(ctx, list,
client.InNamespace(gitrepo.Namespace),
client.MatchingFields{
config.ImageScanGitRepoIndex: gitrepo.Name,
},
); err != nil {
return nil, err
}
return list, nil
}

func GetNamespaceAndNameID(namespace, name string) string {
return fmt.Sprintf("%s/%s", namespace, name)
}
Comment on lines +663 to +665
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If we get rid of the commented out code above, then this function is no longer needed.


func generationChanged(r *v1alpha1.GitRepo) bool {
// checks if generation changed.
// it ignores the case when Status.ObservedGeneration=0 because that's
Expand Down Expand Up @@ -837,3 +901,27 @@ func getNextCommit(status v1alpha1.GitRepoStatus) string {

return commit
}

func batchDeleteDependentResources(ctx context.Context, c client.Client, list client.ObjectList) error {
var errs []error

_ = meta.EachListItem(list, func(obj runtime.Object) error {
o, ok := obj.(client.Object)
if !ok {
errs = append(errs, fmt.Errorf("item does not implement client.Object: %T", obj))
return nil // continue iterating
}
if o.GetDeletionTimestamp() != nil {
// already being deleted
return nil
}

if err := c.Delete(ctx, o); err != nil {
errs = append(errs, err)
}

return nil // continue iterating no matter what
})

return errors.Join(errs...)
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This will format errors with a newline between each error message (skipping nil errors). I'm not sure how well that would work in the Rancher UI.
This may not be critical, but perhaps something to test.

}
Loading