SIGN IN SIGN UP

fix(dnsmanager): scope IP-to-domain resolution cache per container (#939)

* fix(dnsmanager): scope IP-to-domain resolution cache per container

- Scope addressToDomainMap in DNSManager per container using containerToAddressToDomain maps.SafeMap to prevent cross-container DNS attribution and Anycast/CDN IP collision poisoning.
- Pass containerID to DNSResolver.ResolveIPAddress in createNetworkNeighbor and buildNetworkEvent so NetworkNeighborhood egress only carries domains resolved by that specific container.
- Clean up per-container IP-to-domain resolution caches on container removal events.
- Update DNSResolver, DnsCache interfaces, mocks, and tests.
- Add unit tests verifying container DNS isolation and lifecycle cleanup.

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>

* fix(dnsmanager): harden cache lifecycle, prevent resurrection, and thread containerID

- Add removedContainers cache to prevent resurrecting abandoned caches for removed containers upon late-arriving DNS events.
- Add dedicated hostAddressToDomain cache for host and unscoped traffic.
- Synchronize eager cache creation in ContainerCallback with lazy creation.
- Thread containerID parameter through getEgressNetworkNeighbors, getIngressNetworkNeighbors, and createNetworkNeighbor to avoid depending on nilable watchedContainerData.
- Add test assertion verifying late-arriving DNS events after container removal do not recreate caches.

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>

* fix(dnsmanager): bound per-container cache size and make AddContainer initialization idempotent

- Set defaultPerContainerCacheSize to 1000 so nodes with many containers scale memory predictably without allocating node-wide cache capacity per container.
- Make ContainerCallback EventTypeAddContainer check Has(containerID) before allocating to avoid clobbering an existing cache initialized by pre-announcement DNS events.
- Restore Fatal on invalid size during CreateDNSManager.

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>

* fix(dnsmanager): add removal grace period and reject in-flight events for removed containers

- Allow reading existing resolutions during removal grace period so terminal container profile saves retain DNS names.
- Reject in-flight DNS ReportEvents for containers marked as removed to avoid resurrecting abandoned caches.
- Synchronize tombstone removal and cache creation under cacheMu in AddContainer.

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>

* fix(dnsmanager): align removal grace period with containerprofilecache and support host container matching

- Treat armotypes.HostContainerID and empty string uniformly via isHost.
- Align defaultRemovalGracePeriod to 10s matching containerprofilecache.
- Support containerID-keyed lookups in RuleObjectCacheMock.
- Make containerToCloudServices initialization idempotent.

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>

* fix(dns,profile): handle non-positive dnsCacheSize and preserve host key in createNetworkNeighbor

* fix(dnsmanager): use purely lazy per-container cache allocation and check error on removedContainers

- Remove redundant eager pre-allocation in AddContainer to save memory for DNS-inactive containers.
- Check and handle error on removedCache creation in CreateDNSManager.
- Run gofmt on const block.

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>

* fix(dnsmanager): bound containerToAddressToDomain via LRU cache and test mock lookup

- Back containerToAddressToDomain with an LRU cache bounded to maxTrackedContainers (5000), guaranteeing aggregate memory cannot grow unbounded even under container churn.
- Add unit test for RuleObjectCacheMock.ResolveIpToDomain testing both composite-key and fallback resolution.

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>

* fix(dnsmanager): disallow empty containerID fallback to host and scale container LRU with size

- Require explicit armotypes.HostContainerID for host DNS cache access; empty containerID safely misses to prevent cross-container leakage.
- Scale containerCache capacity proportionally with configured cache size to strictly bound total memory budget.

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>

* fix(dnsmanager): reset container cache on AddContainer and filter empty address strings

- Evict any previous cache instance in AddContainer on container ID reuse.
- Filter empty address strings across all lookup and caching paths in ReportEvent.

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>

* fix(dnsmanager): preserve pre-announcement DNS cache in AddContainer and decouple timer cleanup from tombstone LRU

- Do not clear cache in AddContainer to avoid discarding resolutions from early DNS events.
- In removal grace timer, check containerToCloudServices.Has to ensure removal even if tombstone was evicted under high churn.

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>

* fix(dnsmanager): address copilot review comments on cache sizing and initialisms

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>

* test(component): stabilize Test_30 and DaemonSet restart wait

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>

---------

Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>
M
Matthias Bertschy committed
1243ba3eefd8ed8a7541ceeff1d3c212f00e5358
Parent: 9c31a9d
Committed by GitHub <noreply@github.com> on 9/1/2026, 10:25:13 AM