Documentation
¶
Index ¶
- Constants
- func CertificateOwnersForSecret(ctx context.Context, clients *Clients, namespace, secretName string) ([]string, error)
- func CheckCRDExists(ctx context.Context, clients *Clients, name string) error
- func CheckCertificate(ctx context.Context, clients *Clients, namespace, name string) error
- func CheckClusterIssuer(ctx context.Context, clients *Clients, name string) error
- func CheckRegistryIngressDowngrade(desiredRuleHosts, desiredTLSHosts, liveRuleHosts, liveTLSHosts []string) error
- func CheckRegistryIngressManifest(ctx context.Context, clients *Clients, manifest string) error
- func ChooseRegistryPublicHost(s RegistryHostSources) (string, string)
- func ClusterIssuerUsesACME(ctx context.Context, clients *Clients, name string) (bool, error)
- func ConfigMapData(ctx context.Context, clients *Clients, namespace, name string) (map[string]string, error)
- func DeleteJob(ctx context.Context, clients *Clients, namespace, name string, ...) error
- func DeploymentExists(ctx context.Context, clients *Clients, namespace, name string) (bool, error)
- func EnsureNamespace(ctx context.Context, clients *Clients, name string, labels map[string]string) error
- func GetCertificateDNSNames(ctx context.Context, clients *Clients, namespace, name string) ([]string, error)
- func GetDeployment(ctx context.Context, clients *Clients, namespace, name string) (*appsv1.Deployment, error)
- func GetFirstReadyPodName(ctx context.Context, clients *Clients, namespace, labelSelector string) (string, error)
- func GetNamespace() string
- func HTTPStatusFromK8sError(err error) (int, string)
- func IsCRDTerminating(ctx context.Context, clients *Clients, name string) (bool, error)
- func IsInCluster() bool
- func IsJobFailed(ctx context.Context, clients *Clients, namespace, name string) (bool, error)
- func IsNamespaceTerminating(ctx context.Context, clients *Clients, name string) (bool, error)
- func IsPlaceholderRegistryHost(host string) bool
- func ListDeploymentNamespacesByName(ctx context.Context, clients *Clients, name string) ([]string, error)
- func ListFailedCertificateRequestNames(ctx context.Context, clients *Clients, namespace string) ([]string, error)
- func NodeArchitectures(ctx context.Context, clients *Clients) ([]string, error)
- func PatchDeploymentJSON(ctx context.Context, clients *Clients, namespace, name string, patch []byte) error
- func PersistentVolumeClaimStorage(ctx context.Context, clients *Clients, namespace, name string) (string, error)
- func PruneTerminatedPods(ctx context.Context, clients *Clients, namespace string) ([]string, error)
- func RemoveIngressAnnotation(ctx context.Context, clients *Clients, namespace, name, key string) error
- func ResolveRegistryPublicHost(ctx context.Context, clients *Clients, explicit string) (string, string)
- func RestartDeployment(ctx context.Context, clients *Clients, namespace, name string, now time.Time) error
- func SecretExists(ctx context.Context, clients *Clients, namespace, name string) (bool, error)
- func SecretStringDataValue(ctx context.Context, clients *Clients, namespace, name, key string) (string, error)
- func SetDeploymentEnv(ctx context.Context, clients *Clients, namespace, name string, ...) error
- func SetIngressAnnotation(ctx context.Context, clients *Clients, namespace, name, key, value string) error
- func UpdatePersistentVolumeClaimStorage(ctx context.Context, clients *Clients, namespace, name, storageSize string) error
- func UpsertDockerConfigSecret(ctx context.Context, clients *Clients, ...) error
- func UpsertOpaqueSecretStringData(ctx context.Context, clients *Clients, namespace, name string, ...) error
- func WaitForCertificateReady(ctx context.Context, clients *Clients, namespace, name string, ...) error
- func WaitForDaemonSetReady(ctx context.Context, clients *Clients, namespace, name string, ...) error
- func WaitForDeploymentAvailable(ctx context.Context, clients *Clients, namespace, name string, ...) error
- func WaitForDeploymentRolledOut(ctx context.Context, clients *Clients, namespace, name string, ...) error
- func WaitForJobComplete(ctx context.Context, clients *Clients, namespace, name string, ...) error
- func WaitForStatefulSetReady(ctx context.Context, clients *Clients, namespace, name string, ...) error
- func WaitForWorkloadRollout(ctx context.Context, clients *Clients, namespace, kind, name string, ...) error
- type ApplyResult
- func ApplyManifestDir(ctx context.Context, clients *Clients, dir, namespace string) ([]ApplyResult, error)
- func ApplyManifestFile(ctx context.Context, clients *Clients, path, namespace string) ([]ApplyResult, error)
- func ApplyManifestYAML(ctx context.Context, clients *Clients, manifest []byte, namespace string) ([]ApplyResult, error)
- type Clients
- type Config
- type RegistryHostSources
Constants ¶
const ( // RegistryIngressNamespace and RegistryIngressName identify the bundled // registry Ingress that nodes pull through on public installs. RegistryIngressNamespace = "registry" RegistryIngressName = "registry" // RegistryPlaceholderHost is the dev placeholder host baked into // config/registry manifests. RegistryPlaceholderHost = "registry.local" )
const ( RegistryHostSourceExplicit = "explicit" RegistryHostSourceIngressTLS = "registry Ingress TLS host" RegistryHostSourceIngressRule = "registry Ingress rule host" RegistryHostSourceConfigHost = "mcp-shared-config MCP_REGISTRY_INGRESS_HOST" RegistryHostSourceConfigDomain = "mcp-shared-config MCP_PLATFORM_DOMAIN" RegistryHostSourcePlaceholder = "default placeholder" )
Registry public host sources, in precedence order.
Variables ¶
This section is empty.
Functions ¶
func CheckCRDExists ¶
CheckCRDExists verifies that a CRD exists.
func CheckCertificate ¶
func CheckClusterIssuer ¶
func CheckRegistryIngressDowngrade ¶
func CheckRegistryIngressDowngrade(desiredRuleHosts, desiredTLSHosts, liveRuleHosts, liveTLSHosts []string) error
CheckRegistryIngressDowngrade refuses a registry Ingress whose rule host is the placeholder while the desired TLS hosts or the live Ingress already name a public host. Traefik matches routers on the rule host, so that combination returns a plain 404 for every request to the public registry hostname and breaks node image pulls.
func CheckRegistryIngressManifest ¶
CheckRegistryIngressManifest runs CheckRegistryIngressDowngrade for the registry Ingress in a rendered multi-document manifest against the live object. Used by kubectl-based apply paths that bypass ApplyManifestYAML.
func ChooseRegistryPublicHost ¶
func ChooseRegistryPublicHost(s RegistryHostSources) (string, string)
ChooseRegistryPublicHost picks the registry public host. An explicit non-placeholder value wins (setup changing the domain on purpose); otherwise authoritative cluster state wins over the placeholder, so an env-less caller never downgrades a public host to registry.local.
func ClusterIssuerUsesACME ¶
func ConfigMapData ¶
func ConfigMapData(ctx context.Context, clients *Clients, namespace, name string) (map[string]string, error)
ConfigMapData returns a ConfigMap's data, or an empty map when it does not exist.
func DeleteJob ¶
func DeleteJob(ctx context.Context, clients *Clients, namespace, name string, timeout time.Duration) error
DeleteJob deletes a Job and waits briefly for it to disappear.
func DeploymentExists ¶
DeploymentExists returns true when the named Deployment exists in namespace.
func EnsureNamespace ¶
func EnsureNamespace(ctx context.Context, clients *Clients, name string, labels map[string]string) error
EnsureNamespace creates or updates a namespace, preserving existing labels unless the same label key is supplied.
func GetCertificateDNSNames ¶
func GetCertificateDNSNames(ctx context.Context, clients *Clients, namespace, name string) ([]string, error)
GetCertificateDNSNames returns the spec.dnsNames from a cert-manager Certificate. Returns nil, nil when the Certificate does not exist or cert-manager CRDs are not installed.
func GetDeployment ¶
func GetFirstReadyPodName ¶
func GetFirstReadyPodName(ctx context.Context, clients *Clients, namespace, labelSelector string) (string, error)
GetFirstReadyPodName returns the name of the first Ready pod matching labelSelector in namespace, or "" when none is found.
func GetNamespace ¶
func GetNamespace() string
GetNamespace returns the current namespace or "default".
func HTTPStatusFromK8sError ¶
HTTPStatusFromK8sError maps a Kubernetes client/API error to an HTTP status and a short message suitable for JSON API responses.
func IsCRDTerminating ¶
IsCRDTerminating returns true when the named CRD exists and has a deletionTimestamp (stuck in Terminating). Returns false when not found.
func IsInCluster ¶
func IsInCluster() bool
IsInCluster returns true if running inside a Kubernetes cluster.
func IsJobFailed ¶
IsJobFailed returns true when the named Job exists and has at least one failed condition, meaning it will not self-recover. Returns false when the Job does not exist or its status cannot be determined.
func IsNamespaceTerminating ¶
IsNamespaceTerminating returns true when the namespace exists and is stuck in Terminating phase (deletionTimestamp set). Returns false when the namespace does not exist or is healthy.
func IsPlaceholderRegistryHost ¶
IsPlaceholderRegistryHost reports whether host is empty or a dev-only placeholder that no public client or node can pull from.
func ListDeploymentNamespacesByName ¶
func ListDeploymentNamespacesByName(ctx context.Context, clients *Clients, name string) ([]string, error)
ListDeploymentNamespacesByName returns namespaces containing a Deployment with the given name.
func ListFailedCertificateRequestNames ¶
func ListFailedCertificateRequestNames(ctx context.Context, clients *Clients, namespace string) ([]string, error)
ListFailedCertificateRequestNames returns names of CertificateRequests in namespace whose Ready condition is False. Returns nil when the namespace or CRDs don't exist.
func NodeArchitectures ¶
NodeArchitectures returns sorted unique node CPU architectures.
func PatchDeploymentJSON ¶
func PersistentVolumeClaimStorage ¶
func PersistentVolumeClaimStorage(ctx context.Context, clients *Clients, namespace, name string) (string, error)
PersistentVolumeClaimStorage returns the requested storage size for a PVC.
func PruneTerminatedPods ¶
PruneTerminatedPods deletes pods in a namespace that are terminal leftovers of eviction or restart churn: pods in the Failed phase (Evicted, Error, ContainerStatusUnknown, ...) and Succeeded pods that no Job owns. Pods owned by a Job in the Succeeded phase are left to the Job's own lifecycle. Running and Pending pods are never touched. It returns the deleted names.
func RemoveIngressAnnotation ¶
func ResolveRegistryPublicHost ¶
func ResolveRegistryPublicHost(ctx context.Context, clients *Clients, explicit string) (string, string)
ResolveRegistryPublicHost reads the live registry Ingress and platform config ConfigMap and applies ChooseRegistryPublicHost. Read errors are treated as "no cluster state" so fresh installs still work.
func RestartDeployment ¶
func RestartDeployment(ctx context.Context, clients *Clients, namespace, name string, now time.Time) error
RestartDeployment triggers a Deployment rollout by updating the standard restart annotation.
func SecretExists ¶
SecretExists returns true when the named Secret exists in namespace.
func SecretStringDataValue ¶
func SecretStringDataValue(ctx context.Context, clients *Clients, namespace, name, key string) (string, error)
SecretStringDataValue returns one decoded Secret data value, or empty string when either the Secret or key does not exist.
func SetDeploymentEnv ¶
func SetDeploymentEnv(ctx context.Context, clients *Clients, namespace, name string, literals map[string]string, secretName string, secretKeys []string) error
SetDeploymentEnv updates env vars on the first container in a Deployment.
func SetIngressAnnotation ¶
func UpdatePersistentVolumeClaimStorage ¶
func UpdatePersistentVolumeClaimStorage(ctx context.Context, clients *Clients, namespace, name, storageSize string) error
UpdatePersistentVolumeClaimStorage updates the requested storage size on a PVC.
func UpsertDockerConfigSecret ¶
func UpsertDockerConfigSecret(ctx context.Context, clients *Clients, namespace, name, registry, username, password string) error
UpsertDockerConfigSecret creates or updates a dockerconfigjson image pull Secret.
func UpsertOpaqueSecretStringData ¶
func UpsertOpaqueSecretStringData(ctx context.Context, clients *Clients, namespace, name string, data map[string]string) error
UpsertOpaqueSecretStringData creates or updates an Opaque Secret from string data.
func WaitForCertificateReady ¶
func WaitForDaemonSetReady ¶
func WaitForDaemonSetReady(ctx context.Context, clients *Clients, namespace, name string, timeout time.Duration) error
WaitForDaemonSetReady waits until a DaemonSet reports all scheduled replicas ready.
func WaitForDeploymentAvailable ¶
func WaitForDeploymentAvailable(ctx context.Context, clients *Clients, namespace, name string, timeout time.Duration) error
WaitForDeploymentAvailable waits until a Deployment reports at least one available replica.
func WaitForDeploymentRolledOut ¶
func WaitForDeploymentRolledOut(ctx context.Context, clients *Clients, namespace, name string, timeout time.Duration) error
WaitForDeploymentRolledOut waits until the Deployment's current generation has fully rolled out.
func WaitForJobComplete ¶
func WaitForJobComplete(ctx context.Context, clients *Clients, namespace, name string, timeout time.Duration) error
WaitForJobComplete waits until a Job completes or fails.
Types ¶
type ApplyResult ¶
type ApplyResult struct {
GroupVersionKind schema.GroupVersionKind
Namespace string
Name string
Action string
}
ApplyResult describes one object applied through the Kubernetes API.
func ApplyManifestDir ¶
func ApplyManifestDir(ctx context.Context, clients *Clients, dir, namespace string) ([]ApplyResult, error)
ApplyManifestDir applies all .yaml/.yml files in a directory in lexical order.
func ApplyManifestFile ¶
func ApplyManifestFile(ctx context.Context, clients *Clients, path, namespace string) ([]ApplyResult, error)
ApplyManifestFile applies a single manifest file through the Kubernetes API.
func ApplyManifestYAML ¶
func ApplyManifestYAML(ctx context.Context, clients *Clients, manifest []byte, namespace string) ([]ApplyResult, error)
ApplyManifestYAML applies a multi-document Kubernetes manifest through client-go instead of shelling out to kubectl.
func (ApplyResult) String ¶
func (r ApplyResult) String() string
String returns kubectl-like output for CLI callers.
type Clients ¶
type Clients struct {
Clientset kubernetes.Interface
Dynamic dynamic.Interface
Discovery discovery.DiscoveryInterface
Config *rest.Config
Namespace string
}
Clients holds all Kubernetes clients.
func NewFromConfig ¶
NewFromConfig creates clients from an existing rest.Config.
func NewWithConfig ¶
NewWithConfig creates Kubernetes clients with the provided configuration.
type Config ¶
type Config struct {
KubeconfigPath string
}
Config provides Kubernetes client configuration options.
type RegistryHostSources ¶
type RegistryHostSources struct {
Explicit string
IngressTLSHosts []string
IngressRuleHosts []string
ConfigIngressHost string
ConfigPlatformDomain string
}
RegistryHostSources collects every place the registry public host can come from. Explicit is the caller's configured value (env/flag), which may be the placeholder default when the caller's shell has no MCP_* env.