[ONOS-8012] Implement kubernetes network policy store and manager
Change-Id: I0386f1103046f69f5f06586229fb2ac5a0926c15
diff --git a/apps/k8s-networking/app/src/main/java/org/onosproject/k8snetworking/impl/DistributedK8sNetworkPolicyStore.java b/apps/k8s-networking/app/src/main/java/org/onosproject/k8snetworking/impl/DistributedK8sNetworkPolicyStore.java
new file mode 100644
index 0000000..25f34e3
--- /dev/null
+++ b/apps/k8s-networking/app/src/main/java/org/onosproject/k8snetworking/impl/DistributedK8sNetworkPolicyStore.java
@@ -0,0 +1,201 @@
+/*
+ * Copyright 2019-present Open Networking Foundation
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.onosproject.k8snetworking.impl;
+
+import com.google.common.collect.ImmutableSet;
+import io.fabric8.kubernetes.api.model.IntOrString;
+import io.fabric8.kubernetes.api.model.LabelSelector;
+import io.fabric8.kubernetes.api.model.LabelSelectorRequirement;
+import io.fabric8.kubernetes.api.model.ObjectMeta;
+import io.fabric8.kubernetes.api.model.networking.IPBlock;
+import io.fabric8.kubernetes.api.model.networking.NetworkPolicy;
+import io.fabric8.kubernetes.api.model.networking.NetworkPolicyEgressRule;
+import io.fabric8.kubernetes.api.model.networking.NetworkPolicyIngressRule;
+import io.fabric8.kubernetes.api.model.networking.NetworkPolicyPeer;
+import io.fabric8.kubernetes.api.model.networking.NetworkPolicyPort;
+import io.fabric8.kubernetes.api.model.networking.NetworkPolicySpec;
+import org.onlab.util.KryoNamespace;
+import org.onosproject.core.ApplicationId;
+import org.onosproject.core.CoreService;
+import org.onosproject.k8snetworking.api.K8sNetworkPolicyEvent;
+import org.onosproject.k8snetworking.api.K8sNetworkPolicyStore;
+import org.onosproject.k8snetworking.api.K8sNetworkPolicyStoreDelegate;
+import org.onosproject.store.AbstractStore;
+import org.onosproject.store.serializers.KryoNamespaces;
+import org.onosproject.store.service.ConsistentMap;
+import org.onosproject.store.service.MapEvent;
+import org.onosproject.store.service.MapEventListener;
+import org.onosproject.store.service.Serializer;
+import org.onosproject.store.service.StorageService;
+import org.onosproject.store.service.Versioned;
+import org.osgi.service.component.annotations.Activate;
+import org.osgi.service.component.annotations.Component;
+import org.osgi.service.component.annotations.Deactivate;
+import org.osgi.service.component.annotations.Reference;
+import org.osgi.service.component.annotations.ReferenceCardinality;
+import org.slf4j.Logger;
+
+import java.util.LinkedHashMap;
+import java.util.Set;
+import java.util.concurrent.ExecutorService;
+
+import static com.google.common.base.Preconditions.checkArgument;
+import static java.util.concurrent.Executors.newSingleThreadExecutor;
+import static org.onlab.util.Tools.groupedThreads;
+import static org.onosproject.k8snetworking.api.K8sNetworkPolicyEvent.Type.K8S_NETWORK_POLICY_CREATED;
+import static org.onosproject.k8snetworking.api.K8sNetworkPolicyEvent.Type.K8S_NETWORK_POLICY_REMOVED;
+import static org.onosproject.k8snetworking.api.K8sNetworkPolicyEvent.Type.K8S_NETWORK_POLICY_UPDATED;
+import static org.slf4j.LoggerFactory.getLogger;
+
+/**
+ * Implementation of kubernetes network policy store using consistent map.
+ */
+@Component(immediate = true, service = K8sNetworkPolicyStore.class)
+public class DistributedK8sNetworkPolicyStore
+ extends AbstractStore<K8sNetworkPolicyEvent, K8sNetworkPolicyStoreDelegate>
+ implements K8sNetworkPolicyStore {
+
+ private final Logger log = getLogger(getClass());
+
+ private static final String ERR_NOT_FOUND = " does not exist";
+ private static final String ERR_DUPLICATE = " already exists";
+ private static final String APP_ID = "org.onosproject.k8snetwork";
+
+ private static final KryoNamespace
+ SERIALIZER_K8S_NETWORK_POLICY = KryoNamespace.newBuilder()
+ .register(KryoNamespaces.API)
+ .register(NetworkPolicy.class)
+ .register(ObjectMeta.class)
+ .register(NetworkPolicySpec.class)
+ .register(NetworkPolicyIngressRule.class)
+ .register(NetworkPolicyEgressRule.class)
+ .register(LabelSelector.class)
+ .register(NetworkPolicyPeer.class)
+ .register(NetworkPolicyPort.class)
+ .register(IPBlock.class)
+ .register(LabelSelector.class)
+ .register(LabelSelectorRequirement.class)
+ .register(LinkedHashMap.class)
+ .register(IntOrString.class)
+ .build();
+
+ @Reference(cardinality = ReferenceCardinality.MANDATORY)
+ protected CoreService coreService;
+
+ @Reference(cardinality = ReferenceCardinality.MANDATORY)
+ protected StorageService storageService;
+
+ private final ExecutorService eventExecutor = newSingleThreadExecutor(
+ groupedThreads(this.getClass().getSimpleName(), "event-handler", log));
+
+ private final MapEventListener<String, NetworkPolicy> networkPolicyMapListener = new K8sNetworkPolicyMapListener();
+
+ private ConsistentMap<String, NetworkPolicy> networkPolicyStore;
+
+ @Activate
+ protected void activate() {
+ ApplicationId appId = coreService.registerApplication(APP_ID);
+ networkPolicyStore = storageService.<String, NetworkPolicy>consistentMapBuilder()
+ .withSerializer(Serializer.using(SERIALIZER_K8S_NETWORK_POLICY))
+ .withName("k8s-network-policy-store")
+ .withApplicationId(appId)
+ .build();
+
+ networkPolicyStore.addListener(networkPolicyMapListener);
+ log.info("Started");
+ }
+
+ @Deactivate
+ protected void deactivate() {
+ networkPolicyStore.removeListener(networkPolicyMapListener);
+ eventExecutor.shutdown();
+ log.info("Stopped");
+ }
+
+ @Override
+ public void createNetworkPolicy(NetworkPolicy networkPolicy) {
+ networkPolicyStore.compute(networkPolicy.getMetadata().getUid(), (uid, existing) -> {
+ final String error = networkPolicy.getMetadata().getUid() + ERR_DUPLICATE;
+ checkArgument(existing == null, error);
+ return networkPolicy;
+ });
+ }
+
+ @Override
+ public void updateNetworkPolicy(NetworkPolicy networkPolicy) {
+ networkPolicyStore.compute(networkPolicy.getMetadata().getUid(), (uid, existing) -> {
+ final String error = networkPolicy.getMetadata().getUid() + ERR_NOT_FOUND;
+ checkArgument(existing != null, error);
+ return networkPolicy;
+ });
+ }
+
+ @Override
+ public NetworkPolicy removeNetworkPolicy(String uid) {
+ Versioned<NetworkPolicy> networkPolicy = networkPolicyStore.remove(uid);
+ if (networkPolicy == null) {
+ final String error = uid + ERR_NOT_FOUND;
+ throw new IllegalArgumentException(error);
+ }
+ return networkPolicy.value();
+ }
+
+ @Override
+ public NetworkPolicy networkPolicy(String uid) {
+ return networkPolicyStore.asJavaMap().get(uid);
+ }
+
+ @Override
+ public Set<NetworkPolicy> networkPolicies() {
+ return ImmutableSet.copyOf(networkPolicyStore.asJavaMap().values());
+ }
+
+ @Override
+ public void clear() {
+ networkPolicyStore.clear();
+ }
+
+ private class K8sNetworkPolicyMapListener implements MapEventListener<String, NetworkPolicy> {
+
+ @Override
+ public void event(MapEvent<String, NetworkPolicy> event) {
+
+ switch (event.type()) {
+ case INSERT:
+ log.debug("Kubernetes network policy created {}", event.newValue());
+ eventExecutor.execute(() ->
+ notifyDelegate(new K8sNetworkPolicyEvent(
+ K8S_NETWORK_POLICY_CREATED, event.newValue().value())));
+ break;
+ case UPDATE:
+ log.debug("Kubernetes network policy updated {}", event.newValue());
+ eventExecutor.execute(() ->
+ notifyDelegate(new K8sNetworkPolicyEvent(
+ K8S_NETWORK_POLICY_UPDATED, event.newValue().value())));
+ break;
+ case REMOVE:
+ log.debug("Kubernetes network policy removed {}", event.oldValue());
+ eventExecutor.execute(() ->
+ notifyDelegate(new K8sNetworkPolicyEvent(
+ K8S_NETWORK_POLICY_REMOVED, event.oldValue().value())));
+ break;
+ default:
+ // do nothing
+ break;
+ }
+ }
+ }
+}
diff --git a/apps/k8s-networking/app/src/main/java/org/onosproject/k8snetworking/impl/K8sNetworkPolicyManager.java b/apps/k8s-networking/app/src/main/java/org/onosproject/k8snetworking/impl/K8sNetworkPolicyManager.java
new file mode 100644
index 0000000..8f43afd
--- /dev/null
+++ b/apps/k8s-networking/app/src/main/java/org/onosproject/k8snetworking/impl/K8sNetworkPolicyManager.java
@@ -0,0 +1,168 @@
+/*
+ * Copyright 2019-present Open Networking Foundation
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.onosproject.k8snetworking.impl;
+
+import com.google.common.base.Strings;
+import com.google.common.collect.ImmutableSet;
+import io.fabric8.kubernetes.api.model.networking.NetworkPolicy;
+import org.onosproject.core.ApplicationId;
+import org.onosproject.core.CoreService;
+import org.onosproject.event.ListenerRegistry;
+import org.onosproject.k8snetworking.api.K8sNetworkPolicyAdminService;
+import org.onosproject.k8snetworking.api.K8sNetworkPolicyEvent;
+import org.onosproject.k8snetworking.api.K8sNetworkPolicyListener;
+import org.onosproject.k8snetworking.api.K8sNetworkPolicyService;
+import org.onosproject.k8snetworking.api.K8sNetworkPolicyStore;
+import org.onosproject.k8snetworking.api.K8sNetworkPolicyStoreDelegate;
+import org.osgi.service.component.annotations.Activate;
+import org.osgi.service.component.annotations.Component;
+import org.osgi.service.component.annotations.Deactivate;
+import org.osgi.service.component.annotations.Reference;
+import org.osgi.service.component.annotations.ReferenceCardinality;
+import org.slf4j.Logger;
+
+import java.util.Set;
+
+import static com.google.common.base.Preconditions.checkArgument;
+import static com.google.common.base.Preconditions.checkNotNull;
+import static org.onosproject.k8snetworking.api.Constants.K8S_NETWORKING_APP_ID;
+import static org.slf4j.LoggerFactory.getLogger;
+
+/**
+ * Provides implementation of administering and interfacing kubernetes network policy.
+ */
+@Component(
+ immediate = true,
+ service = {K8sNetworkPolicyAdminService.class, K8sNetworkPolicyService.class }
+)
+public class K8sNetworkPolicyManager
+ extends ListenerRegistry<K8sNetworkPolicyEvent, K8sNetworkPolicyListener>
+ implements K8sNetworkPolicyAdminService, K8sNetworkPolicyService {
+
+ protected final Logger log = getLogger(getClass());
+
+ private static final String MSG_NETWORK_POLICY = "Kubernetes network policy %s %s";
+ private static final String MSG_CREATED = "created";
+ private static final String MSG_UPDATED = "updated";
+ private static final String MSG_REMOVED = "removed";
+
+ private static final String
+ ERR_NULL_NETWORK_POLICY = "Kubernetes network policy cannot be null";
+ private static final String
+ ERR_NULL_NETWORK_POLICY_UID = "Kubernetes network policy UID cannot be null";
+
+ private static final String ERR_IN_USE = " still in use";
+
+ @Reference(cardinality = ReferenceCardinality.MANDATORY)
+ protected CoreService coreService;
+
+ @Reference(cardinality = ReferenceCardinality.MANDATORY)
+ protected K8sNetworkPolicyStore k8sNetworkPolicyStore;
+
+ private final K8sNetworkPolicyStoreDelegate
+ delegate = new InternalNetworkPolicyStorageDelegate();
+
+ private ApplicationId appId;
+
+ @Activate
+ protected void activate() {
+ appId = coreService.registerApplication(K8S_NETWORKING_APP_ID);
+
+ k8sNetworkPolicyStore.setDelegate(delegate);
+ log.info("Started");
+ }
+
+ @Deactivate
+ protected void deactivate() {
+ k8sNetworkPolicyStore.unsetDelegate(delegate);
+ log.info("Stopped");
+ }
+
+ @Override
+ public void createNetworkPolicy(NetworkPolicy networkPolicy) {
+ checkNotNull(networkPolicy, ERR_NULL_NETWORK_POLICY);
+ checkArgument(!Strings.isNullOrEmpty(networkPolicy.getMetadata().getUid()),
+ ERR_NULL_NETWORK_POLICY_UID);
+
+ k8sNetworkPolicyStore.createNetworkPolicy(networkPolicy);
+
+ log.info(String.format(MSG_NETWORK_POLICY,
+ networkPolicy.getMetadata().getName(), MSG_CREATED));
+ }
+
+ @Override
+ public void updateNetworkPolicy(NetworkPolicy networkPolicy) {
+ checkNotNull(networkPolicy, ERR_NULL_NETWORK_POLICY);
+ checkArgument(!Strings.isNullOrEmpty(networkPolicy.getMetadata().getUid()),
+ ERR_NULL_NETWORK_POLICY_UID);
+
+ k8sNetworkPolicyStore.updateNetworkPolicy(networkPolicy);
+
+ log.info(String.format(MSG_NETWORK_POLICY,
+ networkPolicy.getMetadata().getName(), MSG_UPDATED));
+ }
+
+ @Override
+ public void removeNetworkPolicy(String uid) {
+ checkArgument(!Strings.isNullOrEmpty(uid), ERR_NULL_NETWORK_POLICY_UID);
+
+ synchronized (this) {
+ if (isNetworkPolicyInUse(uid)) {
+ final String error = String.format(MSG_NETWORK_POLICY, uid, ERR_IN_USE);
+ throw new IllegalStateException(error);
+ }
+
+ NetworkPolicy networkPolicy = k8sNetworkPolicyStore.removeNetworkPolicy(uid);
+
+ if (networkPolicy != null) {
+ log.info(String.format(MSG_NETWORK_POLICY,
+ networkPolicy.getMetadata().getName(), MSG_REMOVED));
+ }
+ }
+ }
+
+ @Override
+ public void clear() {
+ k8sNetworkPolicyStore.clear();
+ }
+
+ @Override
+ public NetworkPolicy networkPolicy(String uid) {
+ checkArgument(!Strings.isNullOrEmpty(uid), ERR_NULL_NETWORK_POLICY_UID);
+ return k8sNetworkPolicyStore.networkPolicy(uid);
+ }
+
+ @Override
+ public Set<NetworkPolicy> networkPolicies() {
+ return ImmutableSet.copyOf(k8sNetworkPolicyStore.networkPolicies());
+ }
+
+ private boolean isNetworkPolicyInUse(String uid) {
+ return false;
+ }
+
+ private class InternalNetworkPolicyStorageDelegate
+ implements K8sNetworkPolicyStoreDelegate {
+
+ @Override
+ public void notify(K8sNetworkPolicyEvent event) {
+ if (event != null) {
+ log.trace("send kubernetes network policy event {}", event);
+ process(event);
+ }
+ }
+ }
+}
diff --git a/apps/k8s-networking/app/src/main/java/org/onosproject/k8snetworking/impl/K8sNetworkPolicyWatcher.java b/apps/k8s-networking/app/src/main/java/org/onosproject/k8snetworking/impl/K8sNetworkPolicyWatcher.java
new file mode 100644
index 0000000..1f8c4a3
--- /dev/null
+++ b/apps/k8s-networking/app/src/main/java/org/onosproject/k8snetworking/impl/K8sNetworkPolicyWatcher.java
@@ -0,0 +1,207 @@
+/*
+ * Copyright 2019-present Open Networking Foundation
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.onosproject.k8snetworking.impl;
+
+import io.fabric8.kubernetes.api.model.networking.NetworkPolicy;
+import io.fabric8.kubernetes.client.KubernetesClient;
+import io.fabric8.kubernetes.client.KubernetesClientException;
+import io.fabric8.kubernetes.client.Watcher;
+import org.onosproject.cluster.ClusterService;
+import org.onosproject.cluster.LeadershipService;
+import org.onosproject.cluster.NodeId;
+import org.onosproject.core.ApplicationId;
+import org.onosproject.core.CoreService;
+import org.onosproject.k8snetworking.api.K8sNetworkPolicyAdminService;
+import org.onosproject.k8snode.api.K8sApiConfigEvent;
+import org.onosproject.k8snode.api.K8sApiConfigListener;
+import org.onosproject.k8snode.api.K8sApiConfigService;
+import org.onosproject.mastership.MastershipService;
+import org.osgi.service.component.annotations.Activate;
+import org.osgi.service.component.annotations.Component;
+import org.osgi.service.component.annotations.Deactivate;
+import org.osgi.service.component.annotations.Reference;
+import org.osgi.service.component.annotations.ReferenceCardinality;
+import org.slf4j.Logger;
+
+import java.util.Objects;
+import java.util.concurrent.ExecutorService;
+
+import static java.util.concurrent.Executors.newSingleThreadExecutor;
+import static org.onlab.util.Tools.groupedThreads;
+import static org.onosproject.k8snetworking.api.Constants.K8S_NETWORKING_APP_ID;
+import static org.onosproject.k8snetworking.util.K8sNetworkingUtil.k8sClient;
+import static org.slf4j.LoggerFactory.getLogger;
+
+/**
+ * Kubernetes network policy watcher used for feeding network policy information.
+ */
+@Component(immediate = true)
+public class K8sNetworkPolicyWatcher {
+
+ private final Logger log = getLogger(getClass());
+
+ @Reference(cardinality = ReferenceCardinality.MANDATORY)
+ protected CoreService coreService;
+
+ @Reference(cardinality = ReferenceCardinality.MANDATORY)
+ protected MastershipService mastershipService;
+
+ @Reference(cardinality = ReferenceCardinality.MANDATORY)
+ protected ClusterService clusterService;
+
+ @Reference(cardinality = ReferenceCardinality.MANDATORY)
+ protected LeadershipService leadershipService;
+
+ @Reference(cardinality = ReferenceCardinality.MANDATORY)
+ protected K8sNetworkPolicyAdminService k8sNetworkPolicyAdminService;
+
+ @Reference(cardinality = ReferenceCardinality.MANDATORY)
+ protected K8sApiConfigService k8sApiConfigService;
+
+ private final ExecutorService eventExecutor = newSingleThreadExecutor(
+ groupedThreads(this.getClass().getSimpleName(), "event-handler"));
+
+ private final InternalK8sNetworkPolicyWatcher
+ internalK8sNetworkPolicyWatcher = new InternalK8sNetworkPolicyWatcher();
+ private final InternalK8sApiConfigListener
+ internalK8sApiConfigListener = new InternalK8sApiConfigListener();
+
+ private ApplicationId appId;
+ private NodeId localNodeId;
+
+ @Activate
+ protected void activate() {
+ appId = coreService.registerApplication(K8S_NETWORKING_APP_ID);
+ localNodeId = clusterService.getLocalNode().id();
+ leadershipService.runForLeadership(appId.name());
+ k8sApiConfigService.addListener(internalK8sApiConfigListener);
+
+ log.info("Started");
+ }
+
+ @Deactivate
+ protected void deactivate() {
+ k8sApiConfigService.removeListener(internalK8sApiConfigListener);
+ leadershipService.withdraw(appId.name());
+ eventExecutor.shutdown();
+
+ log.info("Stopped");
+ }
+
+ private class InternalK8sApiConfigListener implements K8sApiConfigListener {
+
+ private boolean isRelevantHelper() {
+ return Objects.equals(localNodeId, leadershipService.getLeader(appId.name()));
+ }
+
+ @Override
+ public void event(K8sApiConfigEvent event) {
+
+ switch (event.type()) {
+ case K8S_API_CONFIG_UPDATED:
+ eventExecutor.execute(this::processConfigUpdating);
+ break;
+ case K8S_API_CONFIG_CREATED:
+ case K8S_API_CONFIG_REMOVED:
+ default:
+ // do nothing
+ break;
+ }
+ }
+
+ private void processConfigUpdating() {
+ if (!isRelevantHelper()) {
+ return;
+ }
+
+ KubernetesClient client = k8sClient(k8sApiConfigService);
+
+ if (client != null) {
+ client.network().networkPolicies().inAnyNamespace().watch(
+ internalK8sNetworkPolicyWatcher);
+ }
+ }
+ }
+
+ private class InternalK8sNetworkPolicyWatcher implements Watcher<NetworkPolicy> {
+
+ @Override
+ public void eventReceived(Action action, NetworkPolicy service) {
+ switch (action) {
+ case ADDED:
+ eventExecutor.execute(() -> processAddition(service));
+ break;
+ case MODIFIED:
+ eventExecutor.execute(() -> processModification(service));
+ break;
+ case DELETED:
+ eventExecutor.execute(() -> processDeletion(service));
+ break;
+ case ERROR:
+ log.warn("Failures processing network policy manipulation.");
+ break;
+ default:
+ // do nothing
+ break;
+ }
+ }
+
+ @Override
+ public void onClose(KubernetesClientException e) {
+ log.info("Network policy watcher OnClose: {}" + e);
+ }
+
+ private void processAddition(NetworkPolicy networkPolicy) {
+ if (!isMaster()) {
+ return;
+ }
+
+ log.trace("Process network policy {} creating event from API server.",
+ networkPolicy.getMetadata().getName());
+
+ k8sNetworkPolicyAdminService.createNetworkPolicy(networkPolicy);
+ }
+
+ private void processModification(NetworkPolicy networkPolicy) {
+ if (!isMaster()) {
+ return;
+ }
+
+ log.trace("Process network policy {} updating event from API server.",
+ networkPolicy.getMetadata().getName());
+
+ if (k8sNetworkPolicyAdminService.networkPolicy(
+ networkPolicy.getMetadata().getUid()) != null) {
+ k8sNetworkPolicyAdminService.updateNetworkPolicy(networkPolicy);
+ }
+ }
+
+ private void processDeletion(NetworkPolicy networkPolicy) {
+ if (!isMaster()) {
+ return;
+ }
+
+ log.trace("Process network policy {} removal event from API server.",
+ networkPolicy.getMetadata().getName());
+
+ k8sNetworkPolicyAdminService.removeNetworkPolicy(networkPolicy.getMetadata().getUid());
+ }
+
+ private boolean isMaster() {
+ return Objects.equals(localNodeId, leadershipService.getLeader(appId.name()));
+ }
+ }
+}