11use stackable_operator:: {
2- commons:: affinity:: {
3- StackableAffinityFragment , affinity_between_cluster_pods, affinity_between_role_pods,
2+ commons:: {
3+ affinity:: {
4+ StackableAffinityFragment , affinity_between_cluster_pods, affinity_between_role_pods,
5+ } ,
6+ opa:: OpaConfig ,
47 } ,
58 k8s_openapi:: api:: core:: v1:: { PodAffinity , PodAntiAffinity } ,
69} ;
710
811use crate :: crd:: { HdfsNodeRole , constants:: APP_NAME } ;
912
10- pub fn get_affinity ( cluster_name : & str , role : & HdfsNodeRole ) -> StackableAffinityFragment {
13+ /// `opa_config` is only passed for roles that send authorization requests to OPA.
14+ pub fn get_affinity (
15+ cluster_name : & str ,
16+ role : & HdfsNodeRole ,
17+ opa_config : Option < & OpaConfig > ,
18+ ) -> StackableAffinityFragment {
19+ let mut pod_affinities = vec ! [ affinity_between_cluster_pods( APP_NAME , cluster_name, 20 ) ] ;
20+ if let Some ( opa_config) = opa_config {
21+ pod_affinities. push ( affinity_between_role_pods (
22+ "opa" ,
23+ & opa_config. config_map_name , // The discovery cm has the same name as the OpaCluster itself
24+ "server" ,
25+ 50 ,
26+ ) ) ;
27+ }
28+
1129 StackableAffinityFragment {
1230 pod_affinity : Some ( PodAffinity {
13- preferred_during_scheduling_ignored_during_execution : Some ( vec ! [
14- affinity_between_cluster_pods( APP_NAME , cluster_name, 20 ) ,
15- ] ) ,
31+ preferred_during_scheduling_ignored_during_execution : Some ( pod_affinities) ,
1632 required_during_scheduling_ignored_during_execution : None ,
1733 } ) ,
1834 pod_anti_affinity : Some ( PodAntiAffinity {
6379 productVersion: 3.5.0
6480 clusterConfig:
6581 zookeeperConfigMapName: hdfs-zk
82+ authorization:
83+ opa:
84+ configMapName: simple-opa
85+ package: hdfs
6686 journalNodes:
6787 roleGroups:
6888 default:
@@ -80,31 +100,59 @@ spec:
80100 let validated_cluster = deserialize_and_validate_cluster ( input) ;
81101 let merged_config = common_config ( & validated_cluster, & role, & role_group_name ( "default" ) ) ;
82102
103+ let mut expected_pod_affinities = vec ! [ WeightedPodAffinityTerm {
104+ pod_affinity_term: PodAffinityTerm {
105+ label_selector: Some ( LabelSelector {
106+ match_expressions: None ,
107+ match_labels: Some ( BTreeMap :: from( [
108+ ( "app.kubernetes.io/name" . to_string( ) , "hdfs" . to_string( ) ) ,
109+ (
110+ "app.kubernetes.io/instance" . to_string( ) ,
111+ "simple-hdfs" . to_string( ) ,
112+ ) ,
113+ ] ) ) ,
114+ } ) ,
115+ namespace_selector: None ,
116+ namespaces: None ,
117+ topology_key: "kubernetes.io/hostname" . to_string( ) ,
118+ ..PodAffinityTerm :: default ( )
119+ } ,
120+ weight: 20 ,
121+ } ] ;
122+ // Only the NameNode is configured with the OPA authorizer.
123+ if role == HdfsNodeRole :: Name {
124+ expected_pod_affinities. push ( WeightedPodAffinityTerm {
125+ pod_affinity_term : PodAffinityTerm {
126+ label_selector : Some ( LabelSelector {
127+ match_expressions : None ,
128+ match_labels : Some ( BTreeMap :: from ( [
129+ ( "app.kubernetes.io/name" . to_string ( ) , "opa" . to_string ( ) ) ,
130+ (
131+ "app.kubernetes.io/instance" . to_string ( ) ,
132+ "simple-opa" . to_string ( ) ,
133+ ) ,
134+ (
135+ "app.kubernetes.io/component" . to_string ( ) ,
136+ "server" . to_string ( ) ,
137+ ) ,
138+ ] ) ) ,
139+ } ) ,
140+ namespace_selector : None ,
141+ namespaces : None ,
142+ topology_key : "kubernetes.io/hostname" . to_string ( ) ,
143+ ..PodAffinityTerm :: default ( )
144+ } ,
145+ weight : 50 ,
146+ } ) ;
147+ }
148+
83149 assert_eq ! (
84150 merged_config. affinity,
85151 StackableAffinity {
86152 pod_affinity: Some ( PodAffinity {
87- preferred_during_scheduling_ignored_during_execution: Some ( vec![
88- WeightedPodAffinityTerm {
89- pod_affinity_term: PodAffinityTerm {
90- label_selector: Some ( LabelSelector {
91- match_expressions: None ,
92- match_labels: Some ( BTreeMap :: from( [
93- ( "app.kubernetes.io/name" . to_string( ) , "hdfs" . to_string( ) , ) ,
94- (
95- "app.kubernetes.io/instance" . to_string( ) ,
96- "simple-hdfs" . to_string( ) ,
97- ) ,
98- ] ) )
99- } ) ,
100- namespace_selector: None ,
101- namespaces: None ,
102- topology_key: "kubernetes.io/hostname" . to_string( ) ,
103- ..PodAffinityTerm :: default ( )
104- } ,
105- weight: 20
106- }
107- ] ) ,
153+ preferred_during_scheduling_ignored_during_execution: Some (
154+ expected_pod_affinities
155+ ) ,
108156 required_during_scheduling_ignored_during_execution: None ,
109157 } ) ,
110158 pod_anti_affinity: Some ( PodAntiAffinity {
0 commit comments