|
| 1 | +/* Copyright © 2026 Broadcom, Inc. All Rights Reserved. |
| 2 | + SPDX-License-Identifier: Apache-2.0 */ |
| 3 | + |
| 4 | +package main |
| 5 | + |
| 6 | +import ( |
| 7 | + "fmt" |
| 8 | + "os" |
| 9 | + "time" |
| 10 | + |
| 11 | + "k8s.io/apimachinery/pkg/runtime" |
| 12 | + utilruntime "k8s.io/apimachinery/pkg/util/runtime" |
| 13 | + clientgoscheme "k8s.io/client-go/kubernetes/scheme" |
| 14 | + ctrl "sigs.k8s.io/controller-runtime" |
| 15 | + logf "sigs.k8s.io/controller-runtime/pkg/log" |
| 16 | + metricsserver "sigs.k8s.io/controller-runtime/pkg/metrics/server" |
| 17 | + |
| 18 | + vpcv1alpha1 "github.com/vmware-tanzu/nsx-operator/pkg/apis/vpc/v1alpha1" |
| 19 | + "github.com/vmware-tanzu/nsx-operator/pkg/config" |
| 20 | + "github.com/vmware-tanzu/nsx-operator/pkg/eas" |
| 21 | + "github.com/vmware-tanzu/nsx-operator/pkg/eas/server" |
| 22 | + "github.com/vmware-tanzu/nsx-operator/pkg/logger" |
| 23 | + "github.com/vmware-tanzu/nsx-operator/pkg/nsx" |
| 24 | + pkgutil "github.com/vmware-tanzu/nsx-operator/pkg/util" |
| 25 | +) |
| 26 | + |
| 27 | +var ( |
| 28 | + // scheme is the controller-runtime manager's scheme. |
| 29 | + // It only needs types that the VPC info provider and EAS storage layer |
| 30 | + // read from kube-apiserver (VPCNetworkConfiguration, Subnet …). |
| 31 | + // EAS API types (VPCIPAddressUsage etc.) are served entirely from NSX data |
| 32 | + // and live in the generic API server's own scheme (pkg/eas/server/scheme.go). |
| 33 | + scheme = runtime.NewScheme() |
| 34 | +) |
| 35 | + |
| 36 | +func init() { |
| 37 | + utilruntime.Must(clientgoscheme.AddToScheme(scheme)) |
| 38 | + utilruntime.Must(vpcv1alpha1.AddToScheme(scheme)) |
| 39 | +} |
| 40 | + |
| 41 | +func main() { |
| 42 | + // config.AddFlags registers all flags (including -nsxconfig and -log-level) |
| 43 | + // and calls flag.Parse() internally. |
| 44 | + config.AddFlags() |
| 45 | + |
| 46 | + cf, err := config.NewNSXOperatorConfigFromFile() |
| 47 | + if err != nil { |
| 48 | + fmt.Fprintf(os.Stderr, "Failed to read config: %v\n", err) |
| 49 | + os.Exit(1) |
| 50 | + } |
| 51 | + |
| 52 | + log := logger.ZapCustomLogger(cf.DefaultConfig.Debug, config.LogLevel) |
| 53 | + logger.Log = log |
| 54 | + // Register logger with controller-runtime to suppress "log.SetLogger(...) was never called" warning. |
| 55 | + logf.SetLogger(log.Logger) |
| 56 | + |
| 57 | + log.Info("Starting NSX Extension API Server") |
| 58 | + |
| 59 | + // Generate TLS certificates for the EAS HTTPS server. |
| 60 | + // The generic API server (k8s.io/apiserver) uses dynamic certificate loading |
| 61 | + // via dynamiccertificates.NewDynamicServingContentFromFiles, so it |
| 62 | + // automatically picks up renewed cert files without a pod restart. |
| 63 | + // The returned CA PEM is injected into the APIService caBundle so that |
| 64 | + // kube-apiserver can verify the EAS TLS connection. |
| 65 | + caCert, err := pkgutil.GenerateEASCerts() |
| 66 | + if err != nil { |
| 67 | + log.Error(err, "Failed to generate EAS certificates") |
| 68 | + os.Exit(1) |
| 69 | + } |
| 70 | + log.Info("EAS certificates generated successfully") |
| 71 | + go refreshEASCertPeriodically() |
| 72 | + |
| 73 | + // Initialize NSX client. |
| 74 | + nsxClient := nsx.GetClient(cf) |
| 75 | + if nsxClient == nil { |
| 76 | + log.Error(nil, "Failed to get NSX client") |
| 77 | + os.Exit(1) |
| 78 | + } |
| 79 | + log.Info("NSX client initialized") |
| 80 | + |
| 81 | + // Build the k8s rest config and a controller-runtime manager. |
| 82 | + // EAS is read-only so leader election is disabled — all replicas serve |
| 83 | + // concurrently, load-balanced by the kube Service. |
| 84 | + cfg, err := pkgutil.GetConfig() |
| 85 | + if err != nil { |
| 86 | + log.Error(err, "Failed to get REST config for manager") |
| 87 | + os.Exit(1) |
| 88 | + } |
| 89 | + |
| 90 | + // Health and readiness probes are served by the generic API server on the |
| 91 | + // EAS port (default 9553) at /healthz and /readyz over HTTPS. |
| 92 | + // The NSX connectivity check is wired into /readyz via EASServer so that |
| 93 | + // the pod is removed from Service endpoints when NSX is unreachable. |
| 94 | + mgr, err := ctrl.NewManager(cfg, ctrl.Options{ |
| 95 | + Scheme: scheme, |
| 96 | + LeaderElection: false, |
| 97 | + // Metrics and health probes are both handled by the generic API server; |
| 98 | + // disable the controller-runtime sidecars to avoid unused open ports. |
| 99 | + Metrics: metricsserver.Options{BindAddress: "0"}, |
| 100 | + HealthProbeBindAddress: "0", |
| 101 | + }) |
| 102 | + if err != nil { |
| 103 | + log.Error(err, "Failed to create manager") |
| 104 | + os.Exit(1) |
| 105 | + } |
| 106 | + |
| 107 | + vpcProvider := eas.NewK8sVPCInfoProvider(mgr.GetClient()) |
| 108 | + srv := server.NewEASServer(nsxClient, vpcProvider, mgr.GetClient(), cfg, caCert) |
| 109 | + if err := mgr.Add(srv); err != nil { |
| 110 | + log.Error(err, "Failed to add EAS server to manager") |
| 111 | + os.Exit(1) |
| 112 | + } |
| 113 | + |
| 114 | + log.Info("Starting manager") |
| 115 | + if err := mgr.Start(ctrl.SetupSignalHandler()); err != nil { |
| 116 | + log.Error(err, "Failed to start manager") |
| 117 | + os.Exit(1) |
| 118 | + } |
| 119 | +} |
| 120 | + |
| 121 | +// refreshEASCertPeriodically regenerates the EAS TLS certificate every 30 days. |
| 122 | +// The generic API server loads certs via dynamiccertificates.NewDynamicServingContentFromFiles, |
| 123 | +// which watches the cert files for changes and reloads them automatically — so new |
| 124 | +// certs are picked up without a pod restart. |
| 125 | +func refreshEASCertPeriodically() { |
| 126 | + ticker := time.NewTicker(30 * 24 * time.Hour) |
| 127 | + defer ticker.Stop() |
| 128 | + for range ticker.C { |
| 129 | + logger.Log.Info("Refreshing EAS certificates...") |
| 130 | + if _, err := pkgutil.GenerateEASCerts(); err != nil { |
| 131 | + logger.Log.Error(err, "Failed to refresh EAS certificates") |
| 132 | + } else { |
| 133 | + logger.Log.Info("EAS certificates refreshed successfully") |
| 134 | + } |
| 135 | + } |
| 136 | +} |
0 commit comments