controller

package
v0.4.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 9, 2026 License: Apache-2.0 Imports: 37 Imported by: 0

Documentation

Overview

Package controller reconciles the user-facing Gateway CR into a Crossplane XGatewayGCP composite, the WireGuard key Secrets, the in-cluster link Deployment and its RBAC, and an optional DNSEndpoint.

Index

Constants

This section is empty.

Variables

View Source
var XGatewayGCPGVK = schema.GroupVersionKind{Group: "infra.wgnet.dev", Version: "v1alpha1", Kind: "XGatewayGCP"}

XGatewayGCPGVK is the composite's GroupVersionKind, exported so the manager can register an unstructured Owns watch on it.

View Source
var XGatewayNetworkGVK = schema.GroupVersionKind{Group: "infra.wgnet.dev", Version: "v1alpha1", Kind: "XGatewayNetwork"}

XGatewayNetworkGVK is the shared-VPC composite's GroupVersionKind, exported so the manager can register an unstructured watch on it.

Functions

This section is empty.

Types

type Config

type Config struct {
	// LinkImage is the container image for the gateway-link Deployment.
	LinkImage string `envconfig:"GATEWAY_LINK_IMAGE" required:"true"`
	// LinkImagePullPolicy is the imagePullPolicy for the link container.
	LinkImagePullPolicy string `envconfig:"GATEWAY_LINK_IMAGE_PULL_POLICY" default:"IfNotPresent"`

	// UserData is the VM user-data the XGatewayGCP sets on the gateway instance.
	// It is operator-level and byte-identical across Gateways because every
	// per-Gateway value is read from instance metadata at boot. Empty omits the field.
	UserData string `envconfig:"GATEWAY_USER_DATA"`

	// EnableOSLogin turns GCP OS Login on for every gateway VM, gating SSH access
	// through IAM rather than instance metadata keys. Defaults on.
	EnableOSLogin bool `envconfig:"GATEWAY_ENABLE_OSLOGIN" default:"true"`

	// RequeueInterval is how often the reconciler re-polls the XGatewayGCP status,
	// since the composite's status is not watched in realtime.
	RequeueInterval time.Duration `envconfig:"GATEWAY_REQUEUE_INTERVAL" default:"30s"`

	// SharedNetworkName is the GCP VPC every Gateway this operator manages attaches to.
	// Required so a misconfigured install fails fast; separate tenants get distinct
	// values so they never contend for one VPC.
	SharedNetworkName string `envconfig:"GATEWAY_SHARED_NETWORK_NAME" required:"true"`

	// ProviderConfigName is the Crossplane ClusterProviderConfig every composed GCP
	// resource references. Defaults to "default"; set a distinct value to bind an
	// install to its own provider credentials and project.
	ProviderConfigName string `envconfig:"GATEWAY_PROVIDER_CONFIG_NAME" default:"default"`

	// PodNamespace is where the operator pod itself runs, used to place the
	// singleton shared-network composite alongside the operator. Supplied via the
	// downward API.
	PodNamespace string `envconfig:"POD_NAMESPACE" required:"true"`
}

Config carries the operator-level inputs the reconciler folds into every Gateway's children: the values identical across the whole install, not the per-Gateway ones that live on the Gateway spec. It is populated from the process environment.

type GatewayReconciler

type GatewayReconciler struct {
	client.Client
	Scheme   *runtime.Scheme
	Config   Config
	Recorder events.EventRecorder

	// APIReader reads directly from the API server, bypassing the manager cache, for
	// the unwatched, owner-ref-less objects the cache never tracks (the shared
	// XGatewayNetwork, link Leases, and holder pods). SetupWithManager binds it.
	APIReader client.Reader

	// GenerateKey supplies WireGuard keypairs. Nil defaults to wg.GenerateKeypair.
	GenerateKey KeyGenerator
}

GatewayReconciler reconciles a Gateway into its XGatewayGCP composite, WireGuard key Secrets, link Deployment and NetworkPolicy, and optional DNSEndpoint, then mirrors the composite's observed status back onto the Gateway.

func (*GatewayReconciler) Reconcile

func (r *GatewayReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ctrl.Result, error)

Reconcile drives a Gateway toward its desired state: it exposes exactly the valid forward subset and never provisions while all forwards are invalid, but once provisioned keeps its VM rather than tearing down on a transient backend outage.

func (*GatewayReconciler) SetupWithManager

func (r *GatewayReconciler) SetupWithManager(mgr ctrl.Manager) error

SetupWithManager registers the reconciler. The XGatewayGCP watch omits GenerationChangedPredicate so its status-only address writes trigger a reconcile; Service and Namespace watches drive forward classification.

type KeyGenerator

type KeyGenerator func() (privateKey, publicKey string, err error)

KeyGenerator produces a WireGuard keypair. It is injected so tests can supply deterministic key material; production binds it to wg.GenerateKeypair.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL