Conversation
Kimchi Code Review
Summary📊 Review Score: 78/100 (overall code quality — 0 lowest, 100 highest) 🧪 Tests: yes — Unit tests were added for firewall NAT rule generation in 📝 Found 4 issue(s). See inline comments for details. What to expectKimchi will analyze the changes in this pull request and post:
The review typically completes within a few minutes. This comment will be updated once the review is ready. Interact with Kimchi
ConfigurationReviews are configured by your organization admin. Powered by Kimchi — AI-powered code review by CAST AI |
c0dccf4 to
480cdd3
Compare
There was a problem hiding this comment.
📊 Review Score: 78/100 (overall code quality — 0 lowest, 100 highest)
⏱️ Estimated effort to review: 3/5 (1 = trivial, 5 = very complex)
🧪 Tests: yes — Unit tests were added for firewall NAT rule generation in firewall_test.go and for internal-node route/firewall cleanup in internalnode_k8s_test.go. However, no tests cover the new deleteUnknownSourceIP behavior in the ConfigurationReconciler when NodePort support is disabled.
📝 Found 4 issue(s). See inline comments for details.
e8428e2 to
0f33534
Compare
|
/build |
f65623a to
07b5ed0
Compare
07b5ed0 to
f3290fd
Compare
3c6e54e to
5556f2e
Compare
7217c5f to
8832311
Compare
7e751c1 to
87b0a57
Compare
35abf5a to
7603d1d
Compare
7603d1d to
574a9e2
Compare
Restrict pod
IPremapping to provider VirtualNodes, drop the unknown-source IP mapping controller, and fix the gateway remappingFirewallConfigurationto use a single DNAT chain.Changes
IP mapping controller
Deleted the unknown-source IP controller
Removed
pkg/liqo-controller-manager/ipmapping/configuration_controller.go, its test file, and its suite. The controller-manager no longer creates<cfg>-unknown-sourceIPresources. The correspondingCtrlConfigurationIPMappingconstant and main-manager wiring were removed.Create
IPCRs only for pods on provider VirtualNodesUpdated
OffloadedPodReconciler.Reconcileto look up the Node referenced bypod.Spec.NodeNameand verify it carries the standard virtual-node label (liqo.io/type: virtual-node). Only then does it callCreateOrUpdateIP. Pods running on real local nodes are skipped.Added the required
nodesRBAC (get;list;watch) to the reconciler.External-network remapping
FirewallConfigurationenforceFirewallConfigurationChainsnow allocates only one chain (prerouting / DNAT) instead of two. Removed the postrouting / SNAT chain andensureFirewallConfigurationSNATRules, which caused asymmetric NAT and CRD validation errors (nullchains[1]). The masquerade variant remains unchanged.