options.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340
  1. /*
  2. Copyright 2018 The Kubernetes Authors.
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. http://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package options
  14. import (
  15. "fmt"
  16. "net"
  17. "os"
  18. "strconv"
  19. "time"
  20. corev1 "k8s.io/api/core/v1"
  21. metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
  22. "k8s.io/apimachinery/pkg/util/uuid"
  23. apiserveroptions "k8s.io/apiserver/pkg/server/options"
  24. utilfeature "k8s.io/apiserver/pkg/util/feature"
  25. "k8s.io/client-go/informers"
  26. clientset "k8s.io/client-go/kubernetes"
  27. "k8s.io/client-go/kubernetes/scheme"
  28. restclient "k8s.io/client-go/rest"
  29. "k8s.io/client-go/tools/clientcmd"
  30. clientcmdapi "k8s.io/client-go/tools/clientcmd/api"
  31. "k8s.io/client-go/tools/leaderelection"
  32. "k8s.io/client-go/tools/leaderelection/resourcelock"
  33. "k8s.io/client-go/tools/record"
  34. cliflag "k8s.io/component-base/cli/flag"
  35. componentbaseconfig "k8s.io/component-base/config"
  36. "k8s.io/klog"
  37. kubeschedulerconfigv1alpha2 "k8s.io/kube-scheduler/config/v1alpha2"
  38. schedulerappconfig "k8s.io/kubernetes/cmd/kube-scheduler/app/config"
  39. "k8s.io/kubernetes/pkg/client/leaderelectionconfig"
  40. "k8s.io/kubernetes/pkg/master/ports"
  41. "k8s.io/kubernetes/pkg/scheduler"
  42. kubeschedulerconfig "k8s.io/kubernetes/pkg/scheduler/apis/config"
  43. kubeschedulerscheme "k8s.io/kubernetes/pkg/scheduler/apis/config/scheme"
  44. "k8s.io/kubernetes/pkg/scheduler/apis/config/validation"
  45. )
  46. // Options has all the params needed to run a Scheduler
  47. type Options struct {
  48. // The default values. These are overridden if ConfigFile is set or by values in InsecureServing.
  49. ComponentConfig kubeschedulerconfig.KubeSchedulerConfiguration
  50. SecureServing *apiserveroptions.SecureServingOptionsWithLoopback
  51. CombinedInsecureServing *CombinedInsecureServingOptions
  52. Authentication *apiserveroptions.DelegatingAuthenticationOptions
  53. Authorization *apiserveroptions.DelegatingAuthorizationOptions
  54. Deprecated *DeprecatedOptions
  55. // ConfigFile is the location of the scheduler server's configuration file.
  56. ConfigFile string
  57. // WriteConfigTo is the path where the default configuration will be written.
  58. WriteConfigTo string
  59. Master string
  60. }
  61. // NewOptions returns default scheduler app options.
  62. func NewOptions() (*Options, error) {
  63. cfg, err := newDefaultComponentConfig()
  64. if err != nil {
  65. return nil, err
  66. }
  67. hhost, hport, err := splitHostIntPort(cfg.HealthzBindAddress)
  68. if err != nil {
  69. return nil, err
  70. }
  71. o := &Options{
  72. ComponentConfig: *cfg,
  73. SecureServing: apiserveroptions.NewSecureServingOptions().WithLoopback(),
  74. CombinedInsecureServing: &CombinedInsecureServingOptions{
  75. Healthz: (&apiserveroptions.DeprecatedInsecureServingOptions{
  76. BindNetwork: "tcp",
  77. }).WithLoopback(),
  78. Metrics: (&apiserveroptions.DeprecatedInsecureServingOptions{
  79. BindNetwork: "tcp",
  80. }).WithLoopback(),
  81. BindPort: hport,
  82. BindAddress: hhost,
  83. },
  84. Authentication: apiserveroptions.NewDelegatingAuthenticationOptions(),
  85. Authorization: apiserveroptions.NewDelegatingAuthorizationOptions(),
  86. Deprecated: &DeprecatedOptions{
  87. UseLegacyPolicyConfig: false,
  88. PolicyConfigMapNamespace: metav1.NamespaceSystem,
  89. },
  90. }
  91. o.Authentication.TolerateInClusterLookupFailure = true
  92. o.Authentication.RemoteKubeConfigFileOptional = true
  93. o.Authorization.RemoteKubeConfigFileOptional = true
  94. o.Authorization.AlwaysAllowPaths = []string{"/healthz"}
  95. // Set the PairName but leave certificate directory blank to generate in-memory by default
  96. o.SecureServing.ServerCert.CertDirectory = ""
  97. o.SecureServing.ServerCert.PairName = "kube-scheduler"
  98. o.SecureServing.BindPort = ports.KubeSchedulerPort
  99. return o, nil
  100. }
  101. func splitHostIntPort(s string) (string, int, error) {
  102. host, port, err := net.SplitHostPort(s)
  103. if err != nil {
  104. return "", 0, err
  105. }
  106. portInt, err := strconv.Atoi(port)
  107. if err != nil {
  108. return "", 0, err
  109. }
  110. return host, portInt, err
  111. }
  112. func newDefaultComponentConfig() (*kubeschedulerconfig.KubeSchedulerConfiguration, error) {
  113. versionedCfg := kubeschedulerconfigv1alpha2.KubeSchedulerConfiguration{}
  114. kubeschedulerscheme.Scheme.Default(&versionedCfg)
  115. cfg := kubeschedulerconfig.KubeSchedulerConfiguration{}
  116. if err := kubeschedulerscheme.Scheme.Convert(&versionedCfg, &cfg, nil); err != nil {
  117. return nil, err
  118. }
  119. return &cfg, nil
  120. }
  121. // Flags returns flags for a specific scheduler by section name
  122. func (o *Options) Flags() (nfs cliflag.NamedFlagSets) {
  123. fs := nfs.FlagSet("misc")
  124. fs.StringVar(&o.ConfigFile, "config", o.ConfigFile, "The path to the configuration file. Flags override values in this file.")
  125. fs.StringVar(&o.WriteConfigTo, "write-config-to", o.WriteConfigTo, "If set, write the configuration values to this file and exit.")
  126. fs.StringVar(&o.Master, "master", o.Master, "The address of the Kubernetes API server (overrides any value in kubeconfig)")
  127. o.SecureServing.AddFlags(nfs.FlagSet("secure serving"))
  128. o.CombinedInsecureServing.AddFlags(nfs.FlagSet("insecure serving"))
  129. o.Authentication.AddFlags(nfs.FlagSet("authentication"))
  130. o.Authorization.AddFlags(nfs.FlagSet("authorization"))
  131. o.Deprecated.AddFlags(nfs.FlagSet("deprecated"), &o.ComponentConfig)
  132. leaderelectionconfig.BindFlags(&o.ComponentConfig.LeaderElection.LeaderElectionConfiguration, nfs.FlagSet("leader election"))
  133. utilfeature.DefaultMutableFeatureGate.AddFlag(nfs.FlagSet("feature gate"))
  134. return nfs
  135. }
  136. // ApplyTo applies the scheduler options to the given scheduler app configuration.
  137. func (o *Options) ApplyTo(c *schedulerappconfig.Config) error {
  138. if len(o.ConfigFile) == 0 {
  139. c.ComponentConfig = o.ComponentConfig
  140. // only apply deprecated flags if no config file is loaded (this is the old behaviour).
  141. if err := o.Deprecated.ApplyTo(&c.ComponentConfig); err != nil {
  142. return err
  143. }
  144. if err := o.CombinedInsecureServing.ApplyTo(c, &c.ComponentConfig); err != nil {
  145. return err
  146. }
  147. } else {
  148. cfg, err := loadConfigFromFile(o.ConfigFile)
  149. if err != nil {
  150. return err
  151. }
  152. if err := validation.ValidateKubeSchedulerConfiguration(cfg).ToAggregate(); err != nil {
  153. return err
  154. }
  155. // use the loaded config file only, with the exception of --address and --port. This means that
  156. // none of the deprecated flags in o.Deprecated are taken into consideration. This is the old
  157. // behaviour of the flags we have to keep.
  158. c.ComponentConfig = *cfg
  159. if err := o.CombinedInsecureServing.ApplyToFromLoadedConfig(c, &c.ComponentConfig); err != nil {
  160. return err
  161. }
  162. }
  163. if err := o.SecureServing.ApplyTo(&c.SecureServing, &c.LoopbackClientConfig); err != nil {
  164. return err
  165. }
  166. if o.SecureServing != nil && (o.SecureServing.BindPort != 0 || o.SecureServing.Listener != nil) {
  167. if err := o.Authentication.ApplyTo(&c.Authentication, c.SecureServing, nil); err != nil {
  168. return err
  169. }
  170. if err := o.Authorization.ApplyTo(&c.Authorization); err != nil {
  171. return err
  172. }
  173. }
  174. return nil
  175. }
  176. // Validate validates all the required options.
  177. func (o *Options) Validate() []error {
  178. var errs []error
  179. if err := validation.ValidateKubeSchedulerConfiguration(&o.ComponentConfig).ToAggregate(); err != nil {
  180. errs = append(errs, err.Errors()...)
  181. }
  182. errs = append(errs, o.SecureServing.Validate()...)
  183. errs = append(errs, o.CombinedInsecureServing.Validate()...)
  184. errs = append(errs, o.Authentication.Validate()...)
  185. errs = append(errs, o.Authorization.Validate()...)
  186. errs = append(errs, o.Deprecated.Validate()...)
  187. return errs
  188. }
  189. // Config return a scheduler config object
  190. func (o *Options) Config() (*schedulerappconfig.Config, error) {
  191. if o.SecureServing != nil {
  192. if err := o.SecureServing.MaybeDefaultWithSelfSignedCerts("localhost", nil, []net.IP{net.ParseIP("127.0.0.1")}); err != nil {
  193. return nil, fmt.Errorf("error creating self-signed certificates: %v", err)
  194. }
  195. }
  196. c := &schedulerappconfig.Config{}
  197. if err := o.ApplyTo(c); err != nil {
  198. return nil, err
  199. }
  200. // Prepare kube clients.
  201. client, leaderElectionClient, eventClient, err := createClients(c.ComponentConfig.ClientConnection, o.Master, c.ComponentConfig.LeaderElection.RenewDeadline.Duration)
  202. if err != nil {
  203. return nil, err
  204. }
  205. coreBroadcaster := record.NewBroadcaster()
  206. coreRecorder := coreBroadcaster.NewRecorder(scheme.Scheme, corev1.EventSource{Component: c.ComponentConfig.SchedulerName})
  207. // Set up leader election if enabled.
  208. var leaderElectionConfig *leaderelection.LeaderElectionConfig
  209. if c.ComponentConfig.LeaderElection.LeaderElect {
  210. leaderElectionConfig, err = makeLeaderElectionConfig(c.ComponentConfig.LeaderElection, leaderElectionClient, coreRecorder)
  211. if err != nil {
  212. return nil, err
  213. }
  214. }
  215. c.Client = client
  216. c.InformerFactory = informers.NewSharedInformerFactory(client, 0)
  217. c.PodInformer = scheduler.NewPodInformer(client, 0)
  218. c.EventClient = eventClient.EventsV1beta1()
  219. c.CoreEventClient = eventClient.CoreV1()
  220. c.CoreBroadcaster = coreBroadcaster
  221. c.LeaderElection = leaderElectionConfig
  222. return c, nil
  223. }
  224. // makeLeaderElectionConfig builds a leader election configuration. It will
  225. // create a new resource lock associated with the configuration.
  226. func makeLeaderElectionConfig(config kubeschedulerconfig.KubeSchedulerLeaderElectionConfiguration, client clientset.Interface, recorder record.EventRecorder) (*leaderelection.LeaderElectionConfig, error) {
  227. hostname, err := os.Hostname()
  228. if err != nil {
  229. return nil, fmt.Errorf("unable to get hostname: %v", err)
  230. }
  231. // add a uniquifier so that two processes on the same host don't accidentally both become active
  232. id := hostname + "_" + string(uuid.NewUUID())
  233. rl, err := resourcelock.New(config.ResourceLock,
  234. config.ResourceNamespace,
  235. config.ResourceName,
  236. client.CoreV1(),
  237. client.CoordinationV1(),
  238. resourcelock.ResourceLockConfig{
  239. Identity: id,
  240. EventRecorder: recorder,
  241. })
  242. if err != nil {
  243. return nil, fmt.Errorf("couldn't create resource lock: %v", err)
  244. }
  245. return &leaderelection.LeaderElectionConfig{
  246. Lock: rl,
  247. LeaseDuration: config.LeaseDuration.Duration,
  248. RenewDeadline: config.RenewDeadline.Duration,
  249. RetryPeriod: config.RetryPeriod.Duration,
  250. WatchDog: leaderelection.NewLeaderHealthzAdaptor(time.Second * 20),
  251. Name: "kube-scheduler",
  252. }, nil
  253. }
  254. // createClients creates a kube client and an event client from the given config and masterOverride.
  255. // TODO remove masterOverride when CLI flags are removed.
  256. func createClients(config componentbaseconfig.ClientConnectionConfiguration, masterOverride string, timeout time.Duration) (clientset.Interface, clientset.Interface, clientset.Interface, error) {
  257. if len(config.Kubeconfig) == 0 && len(masterOverride) == 0 {
  258. klog.Warningf("Neither --kubeconfig nor --master was specified. Using default API client. This might not work.")
  259. }
  260. // This creates a client, first loading any specified kubeconfig
  261. // file, and then overriding the Master flag, if non-empty.
  262. kubeConfig, err := clientcmd.NewNonInteractiveDeferredLoadingClientConfig(
  263. &clientcmd.ClientConfigLoadingRules{ExplicitPath: config.Kubeconfig},
  264. &clientcmd.ConfigOverrides{ClusterInfo: clientcmdapi.Cluster{Server: masterOverride}}).ClientConfig()
  265. if err != nil {
  266. return nil, nil, nil, err
  267. }
  268. kubeConfig.DisableCompression = true
  269. kubeConfig.AcceptContentTypes = config.AcceptContentTypes
  270. kubeConfig.ContentType = config.ContentType
  271. kubeConfig.QPS = config.QPS
  272. //TODO make config struct use int instead of int32?
  273. kubeConfig.Burst = int(config.Burst)
  274. client, err := clientset.NewForConfig(restclient.AddUserAgent(kubeConfig, "scheduler"))
  275. if err != nil {
  276. return nil, nil, nil, err
  277. }
  278. // shallow copy, do not modify the kubeConfig.Timeout.
  279. restConfig := *kubeConfig
  280. restConfig.Timeout = timeout
  281. leaderElectionClient, err := clientset.NewForConfig(restclient.AddUserAgent(&restConfig, "leader-election"))
  282. if err != nil {
  283. return nil, nil, nil, err
  284. }
  285. eventClient, err := clientset.NewForConfig(kubeConfig)
  286. if err != nil {
  287. return nil, nil, nil, err
  288. }
  289. return client, leaderElectionClient, eventClient, nil
  290. }