Repository navigation
Conversation
The Hetzner API ignores an empty name filter: listing balancers or networks with name= returns everything in the project. A service annotated with an empty balancer name therefore saw every balancer as a candidate. With several it failed as ambiguous, but with a single unlabelled balancer on the same nodes it would adopt and reconfigure a balancer it never created. An empty network name likewise attached the balancer to the only network of the project. Drop every listed balancer or network whose name is not exactly the requested one. An empty name now matches nothing: robotlb goes on to create the balancer and Hetzner rejects the empty name itself, and an empty network name fails as a network that was not found. Assisted-by: LLM Signed-off-by: Aleksei Sviridkin <f@lex.la>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
robotlb should only pick up a balancer or a network whose name is exactly the one it asked for. Today it passes the name as a filter to the Hetzner list endpoint and trusts the result. The API matches names exactly and case-sensitively, but it ignores an empty filter:
GET /load_balancers?name=returns every balancer in the project, andGET /networks?name=returns every network.So a Service annotated with
robotlb/balancer: ""sees all balancers of the project as its own. With several of them, reconciliation fails as ambiguous. With a single unlabelled balancer on the same nodes, robotlb would adopt and reconfigure a balancer it never created. An empty network name has the same effect on a project with one network: the balancer gets attached to it.The fix drops every listed item whose name is not the requested one before the result is used. The legacy-name lookup goes through the same code. Release never looks balancers up by name, so nothing changes there. With an empty balancer name robotlb now tries to create the balancer, Hetzner rejects the empty name, and the error shows up in the warning event. An empty network name fails as a network that was not found.
Unit tests cover the filter for both types. They keep the exact name and drop a case variant, a trailing space, a longer name and the full list returned for an empty name.
A test can't catch the filter being skipped at the two call sites, since they sit in async code that talks to Hetzner.
Stacked on #68.