mirror of
https://github.com/tailscale/tailscale.git
synced 2026-10-09 11:52:00 -04:00
cmd/k8s-operator: base egress Pod readiness on EndpointSlice membership
The egress Pods readiness reconciler decided whether a Pod could route traffic by calling each egress Service's health check through its ClusterIP up to replicas*3 times and looking for a response from that Pod. That is O(replicas) calls per Service per reconcile, and a Pod joining a large ProxyGroup is only sampled 3 times on average, so late Pods often miss and wait for another 5s requeue. The call only goes through kube-proxy on the operator's own node, so it does not show that other nodes route to the Pod either. egress-eps-reconciler already adds a Pod to an egress Service's EndpointSlice only once the Pod's state Secret shows the proxy has set up routing for that Service. This sets the readiness condition once the Pod is an endpoint in an EndpointSlice of every egress Service for the ProxyGroup, and removes the health check calls. Updates tailscale/corp#39464 Signed-off-by: chaosinthecrd <tom@tmlabs.co.uk>
This commit is contained in:
500 Internal Server Error
Gitea Version: 1.28.0+dev-477-g8b6ad49a5f