Skip to content

feat(networking): edge-to-edge resources optimization - #95

Open
cheina97 wants to merge 1 commit into
masterfrom
frc/nodeportdisable
Open

cheina97 wants to merge 1 commit into
masterfrom
frc/nodeportdisable

Conversation

@cheina97

@cheina97 cheina97 commented Sep 9, 2026 •

Copy link
Copy Markdown
Member

Restrict pod IP remapping to provider VirtualNodes, drop the unknown-source IP mapping controller, and fix the gateway remapping FirewallConfiguration to use a single DNAT chain.

Changes

IP mapping controller

  • Deleted the unknown-source IP controller
    Removed pkg/liqo-controller-manager/ipmapping/configuration_controller.go, its test file, and its suite. The controller-manager no longer creates <cfg>-unknown-source IP resources. The corresponding CtrlConfigurationIPMapping constant and main-manager wiring were removed.

  • Create IP CRs only for pods on provider VirtualNodes
    Updated OffloadedPodReconciler.Reconcile to look up the Node referenced by pod.Spec.NodeName and verify it carries the standard virtual-node label (liqo.io/type: virtual-node). Only then does it call CreateOrUpdateIP. Pods running on real local nodes are skipped.

    Added the required nodes RBAC (get;list;watch) to the reconciler.

External-network remapping

  • Single-chain gateway FirewallConfiguration
    enforceFirewallConfigurationChains now allocates only one chain (prerouting / DNAT) instead of two. Removed the postrouting / SNAT chain and ensureFirewallConfigurationSNATRules, which caused asymmetric NAT and CRD validation errors (null chains[1]). The masquerade variant remains unchanged.

@kimchi-review

kimchi-review Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Kimchi Code Review

Property Value
Commit c0dccf4
Author @cheina97
Files changed 23
Review status Completed
Comments 4 (1 info, 3 warning)
Duration 86s

Summary

📊 Review Score: 78/100 (overall code quality — 0 lowest, 100 highest)
⏱️ Estimated effort to review: 3/5 (1 = trivial, 5 = very complex)

🧪 Tests: yes — Unit tests were added for firewall NAT rule generation in firewall_test.go and for internal-node route/firewall cleanup in internalnode_k8s_test.go. However, no tests cover the new deleteUnknownSourceIP behavior in the ConfigurationReconciler when NodePort support is disabled.

📝 Found 4 issue(s). See inline comments for details.

What to expect

Kimchi will analyze the changes in this pull request and post:

  • A summary of the overall changes
  • Inline comments on specific lines with findings categorized by issue type

The review typically completes within a few minutes. This comment will be updated once the review is ready.

Interact with Kimchi
  • @getkimchi review — re-trigger a full review on the latest commit
  • @getkimchi summary — regenerate the PR summary
  • @getkimchi ignore — skip this PR (no review will be posted)
  • Reply to any inline comment to ask follow-up questions or request clarification
Configuration

Reviews are configured by your organization admin.
Review instructions, excluded directories, and severity thresholds can be adjusted per repository in the Kimchi dashboard.


Powered by Kimchi — AI-powered code review by CAST AI

@github-actions github-actions Bot added the feat label Sep 9, 2026
@cheina97
cheina97 force-pushed the frc/nodeportdisable branch from c0dccf4 to 480cdd3 Compare September 9, 2026 12:25

@kimchi-review kimchi-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📊 Review Score: 78/100 (overall code quality — 0 lowest, 100 highest)
⏱️ Estimated effort to review: 3/5 (1 = trivial, 5 = very complex)

🧪 Tests: yes — Unit tests were added for firewall NAT rule generation in firewall_test.go and for internal-node route/firewall cleanup in internalnode_k8s_test.go. However, no tests cover the new deleteUnknownSourceIP behavior in the ConfigurationReconciler when NodePort support is disabled.

📝 Found 4 issue(s). See inline comments for details.

Comment thread pkg/liqo-controller-manager/ipmapping/configuration_controller.go Outdated
Comment thread pkg/liqoctl/test/network/setup/kyverno.go Outdated
Comment thread test/e2e/pipeline/installer/liqo/peer.sh
Comment thread deployments/liqo/values.yaml Outdated
@cheina97
cheina97 force-pushed the frc/nodeportdisable branch 2 times, most recently from e8428e2 to 0f33534 Compare September 9, 2026 13:18
@cheina97

cheina97 commented Sep 9, 2026

Copy link
Copy Markdown
Member Author

/build

@github-actions github-actions Bot added the ci label Sep 9, 2026
@cheina97
cheina97 force-pushed the frc/nodeportdisable branch 2 times, most recently from f65623a to 07b5ed0 Compare September 11, 2026 09:11
@github-actions github-actions Bot added the chore label Sep 14, 2026
@cheina97
cheina97 force-pushed the frc/nodeportdisable branch 7 times, most recently from 3c6e54e to 5556f2e Compare September 17, 2026 08:30
@cheina97 cheina97 changed the title feat: disable nodeport support feat(networking): provider-only IP mapping and single-chain gateway DNAT Sep 17, 2026
@cheina97 cheina97 changed the title feat(networking): provider-only IP mapping and single-chain gateway DNAT feat(networking): edge-to-edge resources optimization Sep 17, 2026
@fra98
fra98 force-pushed the master branch 2 times, most recently from 7217c5f to 8832311 Compare September 21, 2026 07:28
@cheina97
cheina97 force-pushed the frc/nodeportdisable branch 2 times, most recently from 7e751c1 to 87b0a57 Compare September 24, 2026 18:29
@cheina97
cheina97 force-pushed the frc/nodeportdisable branch 3 times, most recently from 35abf5a to 7603d1d Compare September 24, 2026 18:47

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant