云原生后端开发工具微服务【免费下载链接】operator-sdkSDK for building Kubernetes applications. Provides high level APIs, useful abstractions, and project scaffolding.项目地址https://gitcode.com/gh_mirrors/op/operator-sdk点击查看免费下载导读本文以 Operator SDK 仓库中 changelog/generated/v1.16.0.md 发布的 v1.16.0 版本记录为核心系统梳理该版本在 Bundle 校验新增 Good Practices 与 Deprecated APIs 可选校验器、Ansible/Helm/Golang 三类 Operator 的默认资源限制脚手架、以及 Makefile 部署目标uninstall/undeploy的ignore-not-found标志、PHONY 目标等方面的增强。读者读完本文后将掌握 v1.16.0 引入的全部新能力及其源码级实现位置可直接对照升级现有 Operator 项目或在新项目中正确使用这些默认值与校验命令。v1.16.0 版本概览v1.16.0 是 Operator SDK 在 v1.15.0 之后的一个重要迭代版本。从变更记录来看该版本的工作重心集中在四个方面Bundle 校验体系扩展新增good-practices可选校验器并将alpha-deprecated-apis纳入operatorframework套件资源限制resource limits规范化为 Ansible、Helm、Golang 三类 Operator 的脚手架统一补齐默认资源限制值部署流程健壮性为 Golang 项目的uninstall/undeployMakefile 目标增加ignore-not-found标志工程化细节为 Makefile 全部目标补齐 PHONY 声明、统一TODO(user)标记并升级 OPM 与operator_sdk.util依赖版本。下文按 Additions新增、Changes变更、Deprecations弃用、Bug Fixes缺陷修复四个维度逐项展开并结合仓库源码给出实现依据。新增能力AdditionsAnsible Operator 默认资源限制v1.16.0 为 Ansible 类 Operator 的 manager 增加了默认资源限制#5274。脚手架在config/manager/manager.yaml中默认生成如下配置# TODO(user): Configure the resources accordingly based on the project requirements. # More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: limits: cpu: 500m memory: 768Mi requests: cpu: 10m memory: 256Mi配套的升级说明website/content/en/docs/upgrading-sdk-version/v1.16.0.md明确指出设置资源限制是最佳实践上述数值是合理的默认值但 Operator 作者必须根据自身项目需求进行优化调整。指定默认容器注解与 PHONY 目标#5330 引入了两项工程化改进1. 默认容器注解。在config/manager/manager.yaml的 Pod template 中新增注解用于指定kubectl等工具在 Pod 内操作时默认使用的容器template: metadata: annotations: kubectl.kubernetes.io/default-container: manager该注解遵循 Kubernetes 官方的kubectl.kubernetes.io/default-container约定详见 Kubernetes 标签/注解/污点文档可让kubectl logs、kubectl exec等命令自动命中 manager 容器避免在 Pod 存在多个容器时反复指定-c参数。2. Makefile PHONY 目标补齐。v1.16.0 为生成的 Makefile 中所有目标显式声明了.PHONY避免当项目目录中存在与目标同名的文件如名为install、run的文件时导致 Make 误判目标为文件而跳过执行。对照仓库中的样例项目 Makefiletestdata/go/v4/memcached-operator/Makefile可以看到.PHONY: manifests generate fmt vet lint test build run docker-build docker-push bundle bundle-build bundle-push catalogs catalog-build catalog-push clean helpignore-not-found标志让undeploy/uninstall容忍缺失资源同样是 #5330 的成果Golang 项目生成的 Makefile 中uninstall与undeploy目标支持ignore-not-found标志。当 Kustomize 构建出的清单中引用了集群中已不存在的资源例如 CRD 已被手动删除时kubectl delete默认会因 404 报错中断启用该标志后删除流程可以继续执行完剩余资源。实际脚手架实现见 testdata/go/v4/memcached-operator/Makefileifndef ignore-not-found ignore-not-found false endif uninstall: manifests kustomize ## Uninstall CRDs from the K8s cluster specified in ~/.kube/config. Call with ignore-not-foundtrue to ignore resource not found errors during deletion. $(KUSTOMIZE) build config/crd | $(KUBECTL) delete --ignore-not-found$(ignore-not-found) -f - undeploy: kustomize ## Undeploy controller from the K8s cluster specified in ~/.kube/config. Call with ignore-not-foundtrue to ignore resource not found errors during deletion. $(KUSTOMIZE) build config/default | $(KUBECTL) delete --ignore-not-found$(ignore-not-found) -f -调用方式make undeploy ignore-not-foundtrue值得注意的是变更记录原文写作allowsmake undeployandmake installto continue实际上这一特性作用于undeploy与uninstall以及通过相同删除管线执行的清理流程这两个删除型目标其语义是删除时忽略资源不存在错误与安装目标的语义并无直接关联。新增可选校验器Good Practicesv1.16.0 引入了新的可选校验器Good Practices#5448。该校验器依据 operator-framework 解决方案生态中定义的优秀实践标准对 Bundle 进行合规性检查。用法# 按名称选择 operator-sdk bundle validate ./bundle --select-optional namegood-practices # 或按套件选择good-practices 属于 operatorframework 套件 operator-sdk bundle validate ./bundle --select-optional suiteoperatorframework其注册位置在 internal/cmd/operator-sdk/bundle/validate/optional.go{ Validator: apivalidation.GoodPracticesValidator, name: good-practices, labels: map[string]string{ nameKey: good-practices, suiteKey: operatorframework, }, desc: Good Practices bundle validation. This validator validates the bundle against criteria and suggestions defined as good practices for bundles under the operator-framework solutions. More info: https://sdk.operatorframework.io/docs/best-practices/., },从源码可见所有可选校验器都通过name与suite两个标签label进行选择CLI 端--select-optional实际是一个 Kubernetes 标签选择器labels.Selector其匹配逻辑见 optional.go 的checkMatches方法——当用户传入的选择器不匹配任何校验器标签时命令会提前报错退出。新增可选校验器Deprecated APIsalpha-deprecated-apis#5407{ Validator: apivalidation.AlphaDeprecatedAPIsValidator, name: alpha-deprecated-apis, labels: map[string]string{ nameKey: alpha-deprecated-apis, suiteKey: operatorframework, }, desc: (stage: alpha) Deprecated APIs bundle validation. ..., },加入operatorframework套件后一条命令即可同时获得 Good Practices 与弃用 API 两方面的检查结果。可选校验器的完整清单与底层运行机制将上述两个新校验器纳入后v1.16.0 的可选校验器全集如下来源于 optional.go名称标签说明operatorhubv2nameoperatorhubv2,suiteoperatorframeworkOperatorHub.io 元数据校验capabilitiesnamecapabilities,suiteoperatorframeworkOperatorHub.io capabilities 元数据校验categoriesnamecategories,suiteoperatorframeworkOperatorHub.io categories 元数据校验operatorhubnameoperatorhub已弃用的 OperatorHub.io 元数据校验communitynamecommunity(stage: alpha) 社区 Operator Bundle 校验v1.16.0 中已弃用alpha-deprecated-apisnamealpha-deprecated-apis,suiteoperatorframework(stage: alpha) 弃用 API 校验good-practicesnamegood-practices,suiteoperatorframework优秀实践校验multiarchnamemultiarch(Alpha) 多架构支持校验查看完整清单可运行operator-sdk bundle validate --list-optional底层运行逻辑位于 internal/cmd/operator-sdk/bundle/validate/validate.gorun方法先校验 Bundle 格式ValidateBundleFormat与 Bundle 内容ValidateBundleContent随后通过runOptionalValidators(bundle, c.selector, c.optionalValues)执行被选择器命中的可选校验器若用户设置了--optional-values如--optional-valuesk8s-version1.22这些键值对会作为额外对象一并传给校验器见 optional.go。变更内容ChangesOPM 版本升级至 1.19.1#5099 将生成的 Makefile 中默认使用的 OPMOperator Package Manager版本升级到 1.19.1使make catalog-build在 macOS 上也能正常工作。Ansibleoperator_sdk.util模块升级至 0.3.1#5462 将 Ansible Operator 脚手架中requirements.yml引用的operator_sdk.utilAnsible 模块从 0.2.0 提升至 0.3.1。升级时只需更新requirements.yml中的版本号即可。统一TODO(user)标记#5330 为了一致的用户体验确保所有需要用户后续修改的位置都以TODO(user)标记。最典型的就是资源限制配置# TODO(user): Configure the resources accordingly based on the project requirements.Helm Operator 采用与 Golang 相同的资源限制默认值#5330 让 Helm 类 Operator 的脚手架采用与 Golang 项目一致的默认资源限制值保证不同语言类型 Operator 生成的项目在资源配置上的体验统一。Golang 项目默认资源限制值提升同样来自 #5330Golang 类 Operator 脚手架中的默认资源限制值被提高并明确提示用户需根据 Operator 的实际需求优化这些值。这与 Ansible 项目的默认值limits.cpu500m、limits.memory768Mi、requests.cpu10m、requests.memory256Mi保持一致。弃用内容DeprecationsCommunity Operator Bundle 校验stage: alpha弃用#5414 中该校验器仍保留注册名称为community无suite标签但其描述已注明该校验属于 (stage: alpha) 阶段。用户应改用外部校验器完成社区 Operator 目录的合规性验证。缺陷修复Bug FixesOperatorHub.io 校验器补充缺失分类#5375 为operator-sdk bundle validate ./bundle --select-optional nameoperatorhub调用的可选 OperatorHub.io 校验器补上了此前缺失的Modernization Migration分类使该分类下的 Operator 不再被误判为分类缺失。Bundle 校验错误信息改进同一 PR 还改进了 bundle spec 校验中关于无效 ServiceAccount 的错误提示给出更清晰的解释帮助用户快速定位问题。脚手架多行代码片段过滤#5330 改进了脚手架对已有多行代码片段的过滤逻辑参考 kubebuilder 对应的修复避免在重复执行脚手架时产生重复的注释或配置块。升级清单与实操建议综合 v1.16.0 的全部变更若要将既有项目升级到该版本可按以下清单逐项核对Ansible 项目在config/manager/manager.yaml中加入资源限制段见上文默认值并将requirements.yml中的operator_sdk.util更新至 0.3.1所有项目在config/manager/manager.yaml的 Pod template 中加入kubectl.kubernetes.io/default-container: manager注解并核对资源限制配置前的TODO(user)注释是否完整Golang/Helm 项目确认脚手架生成的资源限制默认值已更新Golang 与 Helm 现已统一将 Makefile 中所有目标补上.PHONY声明并为uninstall/undeploy增加ignore-not-found变量与--ignore-not-found$(ignore-not-found)参数可对照 testdata/go/v4/memcached-operator/MakefileBundle 校验开始使用--select-optional suiteoperatorframework或namegood-practices检查 Bundle 优秀实践用namealpha-deprecated-apis检查弃用 API注意community校验器已弃用请改用外部ocp-olm-catalog-validator镜像与目录构建确认 Makefile 中 OPM 版本为 1.19.1保证make catalog-build在 macOS 下可用。相关资源版本变更记录changelog/generated/v1.16.0.md升级指南website/content/en/docs/upgrading-sdk-version/v1.16.0.md可选校验器注册与选择逻辑internal/cmd/operator-sdk/bundle/validate/optional.goBundle 校验主流程internal/cmd/operator-sdk/bundle/validate/validate.go样例项目 Makefile含ignore-not-found与 PHONYtestdata/go/v4/memcached-operator/Makefile脚手架变更片段生成逻辑hack/generate/samples/internal/go/memcached-with-customization/memcached_with_customization.go赞分享云原生后端开发工具微服务【免费下载链接】operator-sdkSDK for building Kubernetes applications. Provides high level APIs, useful abstractions, and project scaffolding.项目地址https://gitcode.com/gh_mirrors/op/operator-sdk点击查看免费下载相关推荐operator-sdk v1.27.0 发布详解run bundle 安全上下文、bundle validate 校验修复与 scorecard 改进operator sdk v1.27.0 发布详解run bundle 安全上下文、bundle validate 校验修复与 scorecard 改进 Op云原生后端开发工具微服务operator-sdk v1.20.0 变更深度解读Bundle 校验增强、Ansible 代理端口可配置与 Related Image 发现重构operator sdk v1.20.0 变更深度解读Bundle 校验增强、Ansible 代理端口可配置与 Related Image 发现重构 本指南基云原生后端开发工具微服务Operator SDK v1.17.0 版本解析混合 Helm 插件、Bundle 校验增强与 Go 1.17 依赖升级Operator SDK v1.17.0 版本解析混合 Helm 插件、Bundle 校验增强与 Go 1.17 依赖升级 本篇文章以 Operator SD云原生后端开发工具微服务上一篇react-slingshot 单元测试覆盖率提升从 0 到 100% 实战下一篇深入原理ocaml-graphql-server如何用Menhir构建纯OCaml的GraphQL解析器创作声明:本文部分内容由AI辅助生成(AIGC),仅供参考