Skip to content

Commit f7fd87c

Browse files
authored
[backport] gateway2: skip non-Gloo Gateways (#10587)
Signed-off-by: Shashank Ram <[email protected]>
1 parent 98f32bc commit f7fd87c

File tree

3 files changed

+33
-14
lines changed

3 files changed

+33
-14
lines changed

changelog/v1.18.7/check-gw.yaml

+7
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
changelog:
2+
- type: FIX
3+
issueLink: https://github.com/solo-io/solo-projects/issues/7768
4+
resolvesIssue: false
5+
description: |
6+
Fixes a bug where we translate Gateways that do not belong to us.
7+

projects/gateway2/controller/start.go

+16-11
Original file line numberDiff line numberDiff line change
@@ -84,11 +84,12 @@ type StartConfig struct {
8484
// It is intended to be run in a goroutine as the function will block until the supplied
8585
// context is cancelled
8686
type ControllerBuilder struct {
87-
proxySyncer *proxy_syncer.ProxySyncer
88-
inputChannels *proxy_syncer.GatewayInputChannels
89-
cfg StartConfig
90-
k8sGwExtensions ext.K8sGatewayExtensions
91-
mgr ctrl.Manager
87+
proxySyncer *proxy_syncer.ProxySyncer
88+
inputChannels *proxy_syncer.GatewayInputChannels
89+
cfg StartConfig
90+
k8sGwExtensions ext.K8sGatewayExtensions
91+
mgr ctrl.Manager
92+
allowedGatewayClasses sets.Set[string]
9293
}
9394

9495
func NewControllerBuilder(ctx context.Context, cfg StartConfig) (*ControllerBuilder, error) {
@@ -170,6 +171,8 @@ func NewControllerBuilder(ctx context.Context, cfg StartConfig) (*ControllerBuil
170171
return nil, err
171172
}
172173

174+
allowedGatewayClasses := sets.New(append(cfg.SetupOpts.ExtraGatewayClasses, wellknown.GatewayClassName)...)
175+
173176
// Create the proxy syncer for the Gateway API resources
174177
setupLog.Info("initializing proxy syncer")
175178
proxySyncer := proxy_syncer.NewProxySyncer(
@@ -190,6 +193,7 @@ func NewControllerBuilder(ctx context.Context, cfg StartConfig) (*ControllerBuil
190193
cfg.SyncerExtensions,
191194
cfg.GlooStatusReporter,
192195
cfg.SetupOpts.ProxyReconcileQueue,
196+
allowedGatewayClasses,
193197
)
194198
proxySyncer.Init(ctx, cfg.Debugger)
195199
if err := mgr.Add(proxySyncer); err != nil {
@@ -198,11 +202,12 @@ func NewControllerBuilder(ctx context.Context, cfg StartConfig) (*ControllerBuil
198202
}
199203

200204
return &ControllerBuilder{
201-
proxySyncer: proxySyncer,
202-
inputChannels: inputChannels,
203-
cfg: cfg,
204-
k8sGwExtensions: k8sGwExtensions,
205-
mgr: mgr,
205+
proxySyncer: proxySyncer,
206+
inputChannels: inputChannels,
207+
cfg: cfg,
208+
k8sGwExtensions: k8sGwExtensions,
209+
mgr: mgr,
210+
allowedGatewayClasses: allowedGatewayClasses,
206211
}, nil
207212
}
208213

@@ -246,7 +251,7 @@ func (c *ControllerBuilder) Start(ctx context.Context) error {
246251

247252
gwCfg := GatewayConfig{
248253
Mgr: c.mgr,
249-
GWClasses: sets.New(append(c.cfg.SetupOpts.ExtraGatewayClasses, wellknown.GatewayClassName)...),
254+
GWClasses: c.allowedGatewayClasses,
250255
ControllerName: wellknown.GatewayControllerName,
251256
AutoProvision: AutoProvision,
252257
ControlPlane: deployer.ControlPlaneInfo{

projects/gateway2/proxy_syncer/proxy_syncer.go

+10-3
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,7 @@ import (
2424
"github.com/solo-io/gloo/projects/gloo/pkg/syncer/setup"
2525
"github.com/solo-io/gloo/projects/gloo/pkg/xds"
2626
rlkubev1a1 "github.com/solo-io/solo-apis/pkg/api/ratelimit.solo.io/v1alpha1"
27+
"k8s.io/apimachinery/pkg/util/sets"
2728

2829
"github.com/solo-io/solo-kit/pkg/api/v1/clients/common"
2930
"github.com/solo-io/solo-kit/pkg/api/v1/clients/kubesecret"
@@ -93,8 +94,9 @@ type ProxySyncer struct {
9394
proxiesToReconcile krt.Singleton[proxyList]
9495
proxyTrigger *krt.RecomputeTrigger
9596

96-
destRules DestinationRuleIndex
97-
translator setup.TranslatorFactory
97+
destRules DestinationRuleIndex
98+
translator setup.TranslatorFactory
99+
allowedGatewayClasses sets.Set[string]
98100

99101
waitForSync []cache.InformerSynced
100102
}
@@ -133,6 +135,7 @@ func NewProxySyncer(
133135
syncerExtensions []syncer.TranslatorSyncerExtension,
134136
glooReporter reporter.StatusReporter,
135137
proxyReconcileQueue ggv2utils.AsyncQueue[gloov1.ProxyList],
138+
allowedGatewayClasses sets.Set[string],
136139
) *ProxySyncer {
137140
return &ProxySyncer{
138141
initialSettings: initialSettings,
@@ -154,7 +157,8 @@ func NewProxySyncer(
154157
// once we audit the plugins to be safe for concurrent use, we can instantiate the translator here.
155158
// this will also have the advantage, that the plugin life-cycle will outlive a single translation
156159
// so that they could own krt collections internally.
157-
translator: translator,
160+
translator: translator,
161+
allowedGatewayClasses: allowedGatewayClasses,
158162
}
159163
}
160164

@@ -409,6 +413,9 @@ func (s *ProxySyncer) Init(ctx context.Context, dbg *krt.DebugHandler) error {
409413
s.proxyTrigger = krt.NewRecomputeTrigger(true)
410414

411415
glooProxies := krt.NewCollection(kubeGateways, func(kctx krt.HandlerContext, gw *gwv1.Gateway) *glooProxy {
416+
if !s.allowedGatewayClasses.Has(string(gw.Spec.GatewayClassName)) {
417+
return nil
418+
}
412419
logger.Debugf("building proxy for kube gw %s version %s", client.ObjectKeyFromObject(gw), gw.GetResourceVersion())
413420
s.proxyTrigger.MarkDependant(kctx)
414421
proxy := s.buildProxy(ctx, gw)

0 commit comments

Comments
 (0)