Conversation
Two clusters running robotlb in one Hetzner project pick the same default name for services with the same name and namespace, and the second one then finds a balancer that is not its own. The new ROBOTLB_CLUSTER_NAME setting puts the cluster in front of the default name. It is checked at startup as a DNS label, so it holds no dot and the full names of different clusters differ. With three labels the name can pass the 128 characters Hetzner allows; such a name is cut and ends in a 64-bit FNV-1a hash of the whole name, so long names that share the kept part still differ. The hash stays the same across releases, as balancers are looked up by name. Names from the balancer annotation are used as given. Unset, names stay as they were. Assisted-by: LLM Signed-off-by: Aleksei Sviridkin <f@lex.la>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two clusters that run robotlb in one Hetzner project give the same default name to balancers of services with the same name and namespace. This adds an optional cluster name that goes in front of the default name, so each cluster gets its own.
The setting is
--cluster-name, orROBOTLB_CLUSTER_NAME. It must be a DNS label: 1 to 63 lowercase letters, digits or-, with a letter or digit at both ends. The operator checks it at startup and stops with an error that names the rule. An empty value, for exampleROBOTLB_CLUSTER_NAME: ""in the chart values, is rejected the same way; to go without a cluster name, leave the variable out. With it set, the default name is<cluster>.<service>.<namespace>. Without it nothing changes and the name stays<service>.<namespace>.Three labels can be up to 191 characters long, and Hetzner takes 128. A longer name is cut to 111 characters and gets
-plus a 16-digit hex FNV-1a 64 hash of the whole name, so two long names that share the first part still differ. Balancers are looked up by this name, so the hash has to stay the same between releases. That's why it is a few lines of inline code pinned by test vectors, and not std's hasher, which gives no such promise.A name from the
robotlb/balancerannotation is used as it is, without the prefix or the hash.Existing balancers are not renamed.
find_hcloud_lblooks for a balancer by therobotlb/service-uidlabel first and only falls back to names when none has it. Every balancer created or adopted by the base branch carries that label. So turning the cluster name on later neither renames nor orphans them. The legacy name of older releases is still tried as before.Tested with
cargo test,cargo clippy --all-targets(no new warnings) andhelm lint helm/. The tests pin the name with and without a cluster name, names of exactly 128 and 129 characters, a 63+63+63 name cut to 128 that still passesvalidate_name, two long names that differ only after the cut, the hash values, an annotated name left alone, and the rejected cluster names: uppercase, a dot,-at either end, underscore, non-ASCII, 64 characters, empty. I broke the code on purpose for each of these and the matching test failed. README andhelm/values.yamldocument the option.Stacked on #67.
Closes #63