fix(dnsmanager): scope IP-to-domain resolution cache per container (#939)
* fix(dnsmanager): scope IP-to-domain resolution cache per container - Scope addressToDomainMap in DNSManager per container using containerToAddressToDomain maps.SafeMap to prevent cross-container DNS attribution and Anycast/CDN IP collision poisoning. - Pass containerID to DNSResolver.ResolveIPAddress in createNetworkNeighbor and buildNetworkEvent so NetworkNeighborhood egress only carries domains resolved by that specific container. - Clean up per-container IP-to-domain resolution caches on container removal events. - Update DNSResolver, DnsCache interfaces, mocks, and tests. - Add unit tests verifying container DNS isolation and lifecycle cleanup. Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com> * fix(dnsmanager): harden cache lifecycle, prevent resurrection, and thread containerID - Add removedContainers cache to prevent resurrecting abandoned caches for removed containers upon late-arriving DNS events. - Add dedicated hostAddressToDomain cache for host and unscoped traffic. - Synchronize eager cache creation in ContainerCallback with lazy creation. - Thread containerID parameter through getEgressNetworkNeighbors, getIngressNetworkNeighbors, and createNetworkNeighbor to avoid depending on nilable watchedContainerData. - Add test assertion verifying late-arriving DNS events after container removal do not recreate caches. Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com> * fix(dnsmanager): bound per-container cache size and make AddContainer initialization idempotent - Set defaultPerContainerCacheSize to 1000 so nodes with many containers scale memory predictably without allocating node-wide cache capacity per container. - Make ContainerCallback EventTypeAddContainer check Has(containerID) before allocating to avoid clobbering an existing cache initialized by pre-announcement DNS events. - Restore Fatal on invalid size during CreateDNSManager. Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com> * fix(dnsmanager): add removal grace period and reject in-flight events for removed containers - Allow reading existing resolutions during removal grace period so terminal container profile saves retain DNS names. - Reject in-flight DNS ReportEvents for containers marked as removed to avoid resurrecting abandoned caches. - Synchronize tombstone removal and cache creation under cacheMu in AddContainer. Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com> * fix(dnsmanager): align removal grace period with containerprofilecache and support host container matching - Treat armotypes.HostContainerID and empty string uniformly via isHost. - Align defaultRemovalGracePeriod to 10s matching containerprofilecache. - Support containerID-keyed lookups in RuleObjectCacheMock. - Make containerToCloudServices initialization idempotent. Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com> * fix(dns,profile): handle non-positive dnsCacheSize and preserve host key in createNetworkNeighbor * fix(dnsmanager): use purely lazy per-container cache allocation and check error on removedContainers - Remove redundant eager pre-allocation in AddContainer to save memory for DNS-inactive containers. - Check and handle error on removedCache creation in CreateDNSManager. - Run gofmt on const block. Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com> * fix(dnsmanager): bound containerToAddressToDomain via LRU cache and test mock lookup - Back containerToAddressToDomain with an LRU cache bounded to maxTrackedContainers (5000), guaranteeing aggregate memory cannot grow unbounded even under container churn. - Add unit test for RuleObjectCacheMock.ResolveIpToDomain testing both composite-key and fallback resolution. Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com> * fix(dnsmanager): disallow empty containerID fallback to host and scale container LRU with size - Require explicit armotypes.HostContainerID for host DNS cache access; empty containerID safely misses to prevent cross-container leakage. - Scale containerCache capacity proportionally with configured cache size to strictly bound total memory budget. Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com> * fix(dnsmanager): reset container cache on AddContainer and filter empty address strings - Evict any previous cache instance in AddContainer on container ID reuse. - Filter empty address strings across all lookup and caching paths in ReportEvent. Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com> * fix(dnsmanager): preserve pre-announcement DNS cache in AddContainer and decouple timer cleanup from tombstone LRU - Do not clear cache in AddContainer to avoid discarding resolutions from early DNS events. - In removal grace timer, check containerToCloudServices.Has to ensure removal even if tombstone was evicted under high churn. Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com> * fix(dnsmanager): address copilot review comments on cache sizing and initialisms Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com> * test(component): stabilize Test_30 and DaemonSet restart wait Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com> --------- Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>
M
Matthias Bertschy committed
1243ba3eefd8ed8a7541ceeff1d3c212f00e5358
Parent: 9c31a9d
Committed by GitHub <noreply@github.com>
on 9/1/2026, 10:25:13 AM