Skip to content

Commit

Permalink
Implement the controller for API BGPPolicy
Browse files Browse the repository at this point in the history
This commit implements the controller of API `BGPPolicy`, designed to advertise
Service IPs, Egress IPs, and Pod IPs to BGP peers from selected Kubernetes Nodes.

According to the spec of `BGPPolicy`, the Node selector is used to select Nodes
to which a `BGPPolicy` is applied. Multiple `BGPPolicies` can be applied to the
same Node. However, only the oldest `BGPPolicy` will be effective on a Node,
with others serving as alternatives. The effective one may be changed in the
following cases:

- The current effective BGPPolicy is updated and not applied to the Node.
- The current effective BGPPolicy is deleted.

The BGP server instance is only created and started for the effective BGPPolicy on
a Node. If the effective BGPPolicy is changed, the corresponding BGP server instance
will be terminated by calling the `Stop` method, and a new BGP server instance will
be created and started by calling the `Start` method for the new effective BGPPolicy.

To create a BGP server instance, ASN, router ID, and listen port must be specified.
The ASN and listen port are specified in the spec of the effective BGPPolicy. For router ID,
if the Kubernetes cluster is IPv4-only or dual-stack, we use the Node's IPv4 address
as the router ID, ensuring uniqueness. If the Kubernetes cluster is IPv6-only, where no
Node IPv4 address is available, the router ID could be specified via the Node annotation
`node.antrea.io/bgp-router-id`. If not present, a router ID will be generated by hashing
the Node name and update it to the Node annotation `node.antrea.io/bgp-router-id`.
Additionally, the stale BGP server instance will be terminated and a new BGP server
instance should be created and started when any of ASN, routerID, or listen port changes.

The information of the BGP peers is specified in the effective BGPPolicy. The unique
identification of a BGP peer is the peer IP address and peer ASN.

To reconcile the latest BGP peers:

- Get the BGP peers to be added and add them by calling the `AddPeer` method of the
  BGP server instance.
- Get the BGP peers to be deleted and delete them by calling the `RemovePeer` method
  of the BGP server instance.
- Get the remaining BGP peers and calculate the updated BGP peers, then update them by
  calling the `UpdatePeer` method of the BGP server instance.

The information of the IPs to be advertised can be calculated from the spec of the
effective BGPPolicy. Currently, we advertise the IPs and CIDRs to all the BGP peers.

To reconcile the latest IPs to all BGP peers:

- If the BGP server instance is newly created and started, advertise all the IPs by
  calling the `AdvertiseRoutes` method.
- If the BGP server instance is not newly created and started:
  - Get the IPs/CIDRs to be added and advertise them by calling the `AdvertiseRoutes` method.
  - Get the IPs/CIDRs to be removed and withdraw them by calling the `WithdrawRoutes` method.

The feature is gated by the alpha `BGPPolicy` feature gate and only supported in Linux.

Signed-off-by: Hongliang Liu <[email protected]>
  • Loading branch information
hongliangl committed Jul 25, 2024
1 parent 02e3a66 commit f124d02
Show file tree
Hide file tree
Showing 8 changed files with 108 additions and 90 deletions.
1 change: 1 addition & 0 deletions build/charts/antrea/templates/agent/clusterrole.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -243,4 +243,5 @@ rules:
- antrea-bgp-passwords
verbs:
- get
- list
- watch
35 changes: 18 additions & 17 deletions build/yamls/antrea-aks.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
# Source: antrea/crds/antreaagentinfo.yaml
# Source: crds/antreaagentinfo.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -152,7 +152,7 @@ spec:
- aai

---
# Source: antrea/crds/antreacontrollerinfo.yaml
# Source: crds/antreacontrollerinfo.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -301,7 +301,7 @@ spec:
- aci

---
# Source: antrea/crds/bgppolicy.yaml
# Source: crds/bgppolicy.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -430,7 +430,7 @@ spec:
kind: BGPPolicy

---
# Source: antrea/crds/clustergroup.yaml
# Source: crds/clustergroup.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -575,7 +575,7 @@ spec:
- cg

---
# Source: antrea/crds/clusternetworkpolicy.yaml
# Source: crds/clusternetworkpolicy.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -1361,7 +1361,7 @@ spec:
- acnp

---
# Source: antrea/crds/egress.yaml
# Source: crds/egress.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -1527,7 +1527,7 @@ spec:
- eg

---
# Source: antrea/crds/externalentity.yaml
# Source: crds/externalentity.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -1582,7 +1582,7 @@ spec:
- ee

---
# Source: antrea/crds/externalippool.yaml
# Source: crds/externalippool.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -1710,7 +1710,7 @@ spec:
- eip

---
# Source: antrea/crds/externalnode.yaml
# Source: crds/externalnode.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -1762,7 +1762,7 @@ spec:
- en

---
# Source: antrea/crds/group.yaml
# Source: crds/group.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -1893,7 +1893,7 @@ spec:
- grp

---
# Source: antrea/crds/ippool.yaml
# Source: crds/ippool.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -2153,7 +2153,7 @@ spec:
- ipp

---
# Source: antrea/crds/networkpolicy.yaml
# Source: crds/networkpolicy.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -2816,7 +2816,7 @@ spec:
- anp

---
# Source: antrea/crds/nodelatencymonitor.yaml
# Source: crds/nodelatencymonitor.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -2867,7 +2867,7 @@ spec:
- nlm

---
# Source: antrea/crds/supportbundlecollection.yaml
# Source: crds/supportbundlecollection.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -3016,7 +3016,7 @@ spec:
- sbc

---
# Source: antrea/crds/tier.yaml
# Source: crds/tier.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -3061,7 +3061,7 @@ spec:
- tr

---
# Source: antrea/crds/traceflow.yaml
# Source: crds/traceflow.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -3371,7 +3371,7 @@ spec:
- tf

---
# Source: antrea/crds/trafficcontrol.yaml
# Source: crds/trafficcontrol.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -4515,6 +4515,7 @@ rules:
- antrea-bgp-passwords
verbs:
- get
- list
- watch
---
# Source: antrea/templates/antctl/clusterrole.yaml
Expand Down
35 changes: 18 additions & 17 deletions build/yamls/antrea-eks.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
# Source: antrea/crds/antreaagentinfo.yaml
# Source: crds/antreaagentinfo.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -152,7 +152,7 @@ spec:
- aai

---
# Source: antrea/crds/antreacontrollerinfo.yaml
# Source: crds/antreacontrollerinfo.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -301,7 +301,7 @@ spec:
- aci

---
# Source: antrea/crds/bgppolicy.yaml
# Source: crds/bgppolicy.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -430,7 +430,7 @@ spec:
kind: BGPPolicy

---
# Source: antrea/crds/clustergroup.yaml
# Source: crds/clustergroup.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -575,7 +575,7 @@ spec:
- cg

---
# Source: antrea/crds/clusternetworkpolicy.yaml
# Source: crds/clusternetworkpolicy.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -1361,7 +1361,7 @@ spec:
- acnp

---
# Source: antrea/crds/egress.yaml
# Source: crds/egress.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -1527,7 +1527,7 @@ spec:
- eg

---
# Source: antrea/crds/externalentity.yaml
# Source: crds/externalentity.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -1582,7 +1582,7 @@ spec:
- ee

---
# Source: antrea/crds/externalippool.yaml
# Source: crds/externalippool.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -1710,7 +1710,7 @@ spec:
- eip

---
# Source: antrea/crds/externalnode.yaml
# Source: crds/externalnode.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -1762,7 +1762,7 @@ spec:
- en

---
# Source: antrea/crds/group.yaml
# Source: crds/group.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -1893,7 +1893,7 @@ spec:
- grp

---
# Source: antrea/crds/ippool.yaml
# Source: crds/ippool.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -2153,7 +2153,7 @@ spec:
- ipp

---
# Source: antrea/crds/networkpolicy.yaml
# Source: crds/networkpolicy.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -2816,7 +2816,7 @@ spec:
- anp

---
# Source: antrea/crds/nodelatencymonitor.yaml
# Source: crds/nodelatencymonitor.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -2867,7 +2867,7 @@ spec:
- nlm

---
# Source: antrea/crds/supportbundlecollection.yaml
# Source: crds/supportbundlecollection.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -3016,7 +3016,7 @@ spec:
- sbc

---
# Source: antrea/crds/tier.yaml
# Source: crds/tier.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -3061,7 +3061,7 @@ spec:
- tr

---
# Source: antrea/crds/traceflow.yaml
# Source: crds/traceflow.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -3371,7 +3371,7 @@ spec:
- tf

---
# Source: antrea/crds/trafficcontrol.yaml
# Source: crds/trafficcontrol.yaml
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
Expand Down Expand Up @@ -4515,6 +4515,7 @@ rules:
- antrea-bgp-passwords
verbs:
- get
- list
- watch
---
# Source: antrea/templates/antctl/clusterrole.yaml
Expand Down
Loading

0 comments on commit f124d02

Please sign in to comment.