2014-07-15 15:34:48 +00:00
|
|
|
/*
|
|
|
|
Copyright 2014 Google Inc. All rights reserved.
|
|
|
|
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
you may not use this file except in compliance with the License.
|
|
|
|
You may obtain a copy of the License at
|
|
|
|
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
See the License for the specific language governing permissions and
|
|
|
|
limitations under the License.
|
|
|
|
*/
|
|
|
|
|
2014-09-09 04:33:17 +00:00
|
|
|
package dockertools
|
2014-07-15 15:34:48 +00:00
|
|
|
|
|
|
|
import (
|
2014-10-14 10:08:48 +00:00
|
|
|
"bufio"
|
|
|
|
"bytes"
|
2014-07-18 14:54:43 +00:00
|
|
|
"errors"
|
2014-07-15 15:34:48 +00:00
|
|
|
"fmt"
|
2014-08-07 23:59:18 +00:00
|
|
|
"hash/adler32"
|
2014-09-24 21:27:10 +00:00
|
|
|
"io"
|
2014-11-07 06:41:16 +00:00
|
|
|
"io/ioutil"
|
2014-07-15 15:34:48 +00:00
|
|
|
"math/rand"
|
2014-10-17 14:05:19 +00:00
|
|
|
"os"
|
2014-08-07 18:15:11 +00:00
|
|
|
"os/exec"
|
2014-09-06 01:13:19 +00:00
|
|
|
"sort"
|
2014-08-07 23:59:18 +00:00
|
|
|
"strconv"
|
2014-07-15 15:34:48 +00:00
|
|
|
"strings"
|
|
|
|
|
|
|
|
"github.com/GoogleCloudPlatform/kubernetes/pkg/api"
|
2014-09-26 04:24:44 +00:00
|
|
|
"github.com/GoogleCloudPlatform/kubernetes/pkg/util"
|
2014-07-15 15:34:48 +00:00
|
|
|
"github.com/fsouza/go-dockerclient"
|
2014-08-07 23:59:18 +00:00
|
|
|
"github.com/golang/glog"
|
2014-07-15 15:34:48 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
// DockerInterface is an abstract interface for testability. It abstracts the interface of docker.Client.
|
|
|
|
type DockerInterface interface {
|
|
|
|
ListContainers(options docker.ListContainersOptions) ([]docker.APIContainers, error)
|
|
|
|
InspectContainer(id string) (*docker.Container, error)
|
|
|
|
CreateContainer(docker.CreateContainerOptions) (*docker.Container, error)
|
|
|
|
StartContainer(id string, hostConfig *docker.HostConfig) error
|
|
|
|
StopContainer(id string, timeout uint) error
|
2014-10-28 00:29:55 +00:00
|
|
|
RemoveContainer(opts docker.RemoveContainerOptions) error
|
2014-09-26 04:53:17 +00:00
|
|
|
InspectImage(image string) (*docker.Image, error)
|
2014-07-15 15:34:48 +00:00
|
|
|
PullImage(opts docker.PullImageOptions, auth docker.AuthConfiguration) error
|
2014-08-27 19:41:32 +00:00
|
|
|
Logs(opts docker.LogsOptions) error
|
2014-10-14 10:08:48 +00:00
|
|
|
Version() (*docker.Env, error)
|
|
|
|
CreateExec(docker.CreateExecOptions) (*docker.Exec, error)
|
|
|
|
StartExec(string, docker.StartExecOptions) error
|
2014-07-15 15:34:48 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// DockerID is an ID of docker container. It is a type to make it clear when we're working with docker container Ids
|
|
|
|
type DockerID string
|
|
|
|
|
|
|
|
// DockerPuller is an abstract interface for testability. It abstracts image pull operations.
|
|
|
|
type DockerPuller interface {
|
|
|
|
Pull(image string) error
|
2014-09-26 04:53:17 +00:00
|
|
|
IsImagePresent(image string) (bool, error)
|
2014-07-15 15:34:48 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// dockerPuller is the default implementation of DockerPuller.
|
|
|
|
type dockerPuller struct {
|
2014-09-06 01:13:19 +00:00
|
|
|
client DockerInterface
|
|
|
|
keyring *dockerKeyring
|
2014-07-15 15:34:48 +00:00
|
|
|
}
|
|
|
|
|
2014-09-26 04:24:44 +00:00
|
|
|
type throttledDockerPuller struct {
|
|
|
|
puller dockerPuller
|
|
|
|
limiter util.RateLimiter
|
|
|
|
}
|
|
|
|
|
2014-07-15 15:34:48 +00:00
|
|
|
// NewDockerPuller creates a new instance of the default implementation of DockerPuller.
|
2014-09-26 04:24:44 +00:00
|
|
|
func NewDockerPuller(client DockerInterface, qps float32, burst int) DockerPuller {
|
2014-09-06 01:13:19 +00:00
|
|
|
dp := dockerPuller{
|
|
|
|
client: client,
|
|
|
|
keyring: newDockerKeyring(),
|
2014-07-15 15:34:48 +00:00
|
|
|
}
|
2014-09-06 01:13:19 +00:00
|
|
|
|
|
|
|
cfg, err := readDockerConfigFile()
|
|
|
|
if err == nil {
|
|
|
|
cfg.addToKeyring(dp.keyring)
|
2014-10-17 14:05:19 +00:00
|
|
|
} else if !os.IsNotExist(err) {
|
|
|
|
glog.V(1).Infof("Unable to parse Docker config file: %v", err)
|
2014-09-06 01:13:19 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
if dp.keyring.count() == 0 {
|
2014-09-18 10:46:14 +00:00
|
|
|
glog.V(1).Infof("Continuing with empty Docker keyring")
|
2014-09-06 01:13:19 +00:00
|
|
|
}
|
2014-09-26 04:24:44 +00:00
|
|
|
if qps == 0.0 {
|
|
|
|
return dp
|
|
|
|
}
|
|
|
|
return &throttledDockerPuller{
|
|
|
|
puller: dp,
|
|
|
|
limiter: util.NewTokenBucketRateLimiter(qps, burst),
|
|
|
|
}
|
2014-07-15 15:34:48 +00:00
|
|
|
}
|
|
|
|
|
2014-10-14 10:08:48 +00:00
|
|
|
type dockerContainerCommandRunner struct {
|
|
|
|
client DockerInterface
|
|
|
|
}
|
|
|
|
|
|
|
|
// The first version of docker that supports exec natively is 1.1.3
|
|
|
|
var dockerVersionWithExec = []uint{1, 1, 3}
|
|
|
|
|
|
|
|
// Returns the major and minor version numbers of docker server.
|
|
|
|
func (d *dockerContainerCommandRunner) getDockerServerVersion() ([]uint, error) {
|
|
|
|
env, err := d.client.Version()
|
|
|
|
if err != nil {
|
|
|
|
return nil, fmt.Errorf("failed to get docker server version - %s", err)
|
|
|
|
}
|
|
|
|
version := []uint{}
|
|
|
|
for _, entry := range *env {
|
|
|
|
if strings.Contains(strings.ToLower(entry), "server version") {
|
|
|
|
elems := strings.Split(strings.Split(entry, "=")[1], ".")
|
|
|
|
for _, elem := range elems {
|
|
|
|
val, err := strconv.ParseUint(elem, 10, 32)
|
|
|
|
if err != nil {
|
|
|
|
return nil, fmt.Errorf("failed to parse docker server version (%s) - %s", entry, err)
|
|
|
|
}
|
|
|
|
version = append(version, uint(val))
|
|
|
|
}
|
|
|
|
return version, nil
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return nil, fmt.Errorf("docker server version missing from server version output - %+v", env)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (d *dockerContainerCommandRunner) nativeExecSupportExists() (bool, error) {
|
|
|
|
version, err := d.getDockerServerVersion()
|
|
|
|
if err != nil {
|
|
|
|
return false, err
|
|
|
|
}
|
|
|
|
if len(dockerVersionWithExec) != len(version) {
|
|
|
|
return false, fmt.Errorf("unexpected docker version format. Expecting %v format, got %v", dockerVersionWithExec, version)
|
|
|
|
}
|
|
|
|
for idx, val := range dockerVersionWithExec {
|
|
|
|
if version[idx] < val {
|
|
|
|
return false, nil
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return true, nil
|
|
|
|
}
|
2014-08-07 18:15:11 +00:00
|
|
|
|
|
|
|
func (d *dockerContainerCommandRunner) getRunInContainerCommand(containerID string, cmd []string) (*exec.Cmd, error) {
|
|
|
|
args := append([]string{"exec"}, cmd...)
|
|
|
|
command := exec.Command("/usr/sbin/nsinit", args...)
|
|
|
|
command.Dir = fmt.Sprintf("/var/lib/docker/execdriver/native/%s", containerID)
|
|
|
|
return command, nil
|
|
|
|
}
|
|
|
|
|
2014-10-14 10:08:48 +00:00
|
|
|
func (d *dockerContainerCommandRunner) runInContainerUsingNsinit(containerID string, cmd []string) ([]byte, error) {
|
2014-08-07 18:15:11 +00:00
|
|
|
c, err := d.getRunInContainerCommand(containerID, cmd)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
return c.CombinedOutput()
|
|
|
|
}
|
|
|
|
|
2014-10-14 10:08:48 +00:00
|
|
|
// RunInContainer uses nsinit to run the command inside the container identified by containerID
|
|
|
|
func (d *dockerContainerCommandRunner) RunInContainer(containerID string, cmd []string) ([]byte, error) {
|
|
|
|
// If native exec support does not exist in the local docker daemon use nsinit.
|
|
|
|
useNativeExec, err := d.nativeExecSupportExists()
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
if !useNativeExec {
|
|
|
|
return d.runInContainerUsingNsinit(containerID, cmd)
|
|
|
|
}
|
|
|
|
createOpts := docker.CreateExecOptions{
|
|
|
|
Container: containerID,
|
|
|
|
Cmd: cmd,
|
|
|
|
AttachStdin: false,
|
|
|
|
AttachStdout: true,
|
|
|
|
AttachStderr: true,
|
|
|
|
Tty: false,
|
|
|
|
}
|
|
|
|
execObj, err := d.client.CreateExec(createOpts)
|
|
|
|
if err != nil {
|
|
|
|
return nil, fmt.Errorf("failed to run in container - Exec setup failed - %s", err)
|
|
|
|
}
|
|
|
|
var buf bytes.Buffer
|
|
|
|
wrBuf := bufio.NewWriter(&buf)
|
|
|
|
startOpts := docker.StartExecOptions{
|
|
|
|
Detach: false,
|
|
|
|
Tty: false,
|
|
|
|
OutputStream: wrBuf,
|
|
|
|
ErrorStream: wrBuf,
|
|
|
|
RawTerminal: false,
|
|
|
|
}
|
|
|
|
errChan := make(chan error, 1)
|
|
|
|
go func() {
|
|
|
|
errChan <- d.client.StartExec(execObj.Id, startOpts)
|
|
|
|
}()
|
|
|
|
wrBuf.Flush()
|
|
|
|
return buf.Bytes(), <-errChan
|
|
|
|
}
|
|
|
|
|
2014-08-07 18:15:11 +00:00
|
|
|
// NewDockerContainerCommandRunner creates a ContainerCommandRunner which uses nsinit to run a command
|
|
|
|
// inside a container.
|
2014-11-05 00:58:37 +00:00
|
|
|
func NewDockerContainerCommandRunner(client DockerInterface) ContainerCommandRunner {
|
|
|
|
return &dockerContainerCommandRunner{client: client}
|
2014-08-07 18:15:11 +00:00
|
|
|
}
|
|
|
|
|
2014-07-15 15:34:48 +00:00
|
|
|
func (p dockerPuller) Pull(image string) error {
|
|
|
|
image, tag := parseImageName(image)
|
2014-07-20 17:31:26 +00:00
|
|
|
|
|
|
|
// If no tag was specified, use the default "latest".
|
|
|
|
if len(tag) == 0 {
|
|
|
|
tag = "latest"
|
|
|
|
}
|
|
|
|
|
2014-07-15 15:34:48 +00:00
|
|
|
opts := docker.PullImageOptions{
|
|
|
|
Repository: image,
|
|
|
|
Tag: tag,
|
|
|
|
}
|
2014-09-06 01:13:19 +00:00
|
|
|
|
|
|
|
creds, ok := p.keyring.lookup(image)
|
|
|
|
if !ok {
|
|
|
|
glog.V(1).Infof("Pulling image %s without credentials", image)
|
|
|
|
}
|
|
|
|
|
|
|
|
return p.client.PullImage(opts, creds)
|
2014-07-15 15:34:48 +00:00
|
|
|
}
|
|
|
|
|
2014-09-26 04:24:44 +00:00
|
|
|
func (p throttledDockerPuller) Pull(image string) error {
|
|
|
|
if p.limiter.CanAccept() {
|
|
|
|
return p.puller.Pull(image)
|
|
|
|
}
|
|
|
|
return fmt.Errorf("pull QPS exceeded.")
|
|
|
|
}
|
|
|
|
|
2014-09-26 04:53:17 +00:00
|
|
|
func (p dockerPuller) IsImagePresent(name string) (bool, error) {
|
|
|
|
image, _ := parseImageName(name)
|
|
|
|
_, err := p.client.InspectImage(image)
|
|
|
|
if err == nil {
|
|
|
|
return true, nil
|
|
|
|
}
|
|
|
|
// This is super brittle, but its the best we got.
|
|
|
|
// TODO: Land code in the docker client to use docker.Error here instead.
|
|
|
|
if err.Error() == "no such image" {
|
|
|
|
return false, nil
|
|
|
|
}
|
|
|
|
return false, err
|
|
|
|
}
|
|
|
|
|
2014-11-14 22:20:29 +00:00
|
|
|
// RequireLatestImage returns if the user wants the latest image
|
|
|
|
func RequireLatestImage(name string) bool {
|
|
|
|
_, tag := parseImageName(name)
|
|
|
|
|
|
|
|
if tag == "latest" {
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
2014-09-26 04:53:17 +00:00
|
|
|
func (p throttledDockerPuller) IsImagePresent(name string) (bool, error) {
|
|
|
|
return p.puller.IsImagePresent(name)
|
|
|
|
}
|
|
|
|
|
2014-07-15 17:26:56 +00:00
|
|
|
// DockerContainers is a map of containers
|
|
|
|
type DockerContainers map[DockerID]*docker.APIContainers
|
|
|
|
|
2014-09-05 09:49:11 +00:00
|
|
|
func (c DockerContainers) FindPodContainer(podFullName, uuid, containerName string) (*docker.APIContainers, bool, uint64) {
|
2014-07-15 17:26:56 +00:00
|
|
|
for _, dockerContainer := range c {
|
2014-10-09 05:31:59 +00:00
|
|
|
// TODO(proppy): build the docker container name and do a map lookup instead?
|
2014-09-09 04:33:17 +00:00
|
|
|
dockerManifestID, dockerUUID, dockerContainerName, hash := ParseDockerName(dockerContainer.Names[0])
|
2014-09-05 09:49:11 +00:00
|
|
|
if dockerManifestID == podFullName &&
|
|
|
|
(uuid == "" || dockerUUID == uuid) &&
|
|
|
|
dockerContainerName == containerName {
|
2014-08-07 23:59:18 +00:00
|
|
|
return dockerContainer, true, hash
|
2014-07-15 17:26:56 +00:00
|
|
|
}
|
|
|
|
}
|
2014-08-07 23:59:18 +00:00
|
|
|
return nil, false, 0
|
2014-07-15 17:26:56 +00:00
|
|
|
}
|
|
|
|
|
2014-09-05 09:49:11 +00:00
|
|
|
// Note, this might return containers belong to a different Pod instance with the same name
|
2014-07-18 18:42:47 +00:00
|
|
|
func (c DockerContainers) FindContainersByPodFullName(podFullName string) map[string]*docker.APIContainers {
|
2014-07-15 17:26:56 +00:00
|
|
|
containers := make(map[string]*docker.APIContainers)
|
|
|
|
|
|
|
|
for _, dockerContainer := range c {
|
2014-09-09 04:33:17 +00:00
|
|
|
dockerManifestID, _, dockerContainerName, _ := ParseDockerName(dockerContainer.Names[0])
|
2014-07-18 18:42:47 +00:00
|
|
|
if dockerManifestID == podFullName {
|
2014-07-15 17:26:56 +00:00
|
|
|
containers[dockerContainerName] = dockerContainer
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return containers
|
|
|
|
}
|
|
|
|
|
2014-09-29 21:38:31 +00:00
|
|
|
// GetKubeletDockerContainers takes client and boolean whether to list all container or just the running ones.
|
|
|
|
// Returns a map of docker containers that we manage. The map key is the docker container ID
|
|
|
|
func GetKubeletDockerContainers(client DockerInterface, allContainers bool) (DockerContainers, error) {
|
2014-07-15 17:26:56 +00:00
|
|
|
result := make(DockerContainers)
|
2014-09-29 21:38:31 +00:00
|
|
|
containers, err := client.ListContainers(docker.ListContainersOptions{All: allContainers})
|
2014-07-15 17:26:56 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
for i := range containers {
|
|
|
|
container := &containers[i]
|
|
|
|
// Skip containers that we didn't create to allow users to manually
|
|
|
|
// spin up their own containers if they want.
|
2014-09-25 00:05:53 +00:00
|
|
|
// TODO(dchen1107): Remove the old separator "--" by end of Oct
|
|
|
|
if !strings.HasPrefix(container.Names[0], "/"+containerNamePrefix+"_") &&
|
|
|
|
!strings.HasPrefix(container.Names[0], "/"+containerNamePrefix+"--") {
|
2014-11-03 16:38:02 +00:00
|
|
|
glog.V(3).Infof("Docker Container: %s is not managed by kubelet.", container.Names[0])
|
2014-07-15 17:26:56 +00:00
|
|
|
continue
|
|
|
|
}
|
|
|
|
result[DockerID(container.ID)] = container
|
|
|
|
}
|
|
|
|
return result, nil
|
|
|
|
}
|
|
|
|
|
2014-09-09 04:33:17 +00:00
|
|
|
// GetRecentDockerContainersWithNameAndUUID returns a list of dead docker containers which matches the name
|
2014-08-26 18:25:17 +00:00
|
|
|
// and uuid given.
|
2014-09-09 04:33:17 +00:00
|
|
|
func GetRecentDockerContainersWithNameAndUUID(client DockerInterface, podFullName, uuid, containerName string) ([]*docker.Container, error) {
|
2014-08-26 18:25:17 +00:00
|
|
|
var result []*docker.Container
|
|
|
|
containers, err := client.ListContainers(docker.ListContainersOptions{All: true})
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
for _, dockerContainer := range containers {
|
2014-09-09 04:33:17 +00:00
|
|
|
dockerPodName, dockerUUID, dockerContainerName, _ := ParseDockerName(dockerContainer.Names[0])
|
2014-08-26 18:25:17 +00:00
|
|
|
if dockerPodName != podFullName {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
if uuid != "" && dockerUUID != uuid {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
if dockerContainerName != containerName {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
inspectResult, _ := client.InspectContainer(dockerContainer.ID)
|
|
|
|
if inspectResult != nil && !inspectResult.State.Running && !inspectResult.State.Paused {
|
|
|
|
result = append(result, inspectResult)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return result, nil
|
|
|
|
}
|
|
|
|
|
2014-08-27 19:41:32 +00:00
|
|
|
// GetKubeletDockerContainerLogs returns logs of specific container
|
2014-09-15 16:20:01 +00:00
|
|
|
// By default the function will return snapshot of the container log
|
|
|
|
// Log streaming is possible if 'follow' param is set to true
|
|
|
|
// Log tailing is possible when number of tailed lines are set and only if 'follow' is false
|
2014-11-12 10:42:55 +00:00
|
|
|
// TODO: Make 'RawTerminal' option flagable.
|
2014-09-22 20:14:23 +00:00
|
|
|
func GetKubeletDockerContainerLogs(client DockerInterface, containerID, tail string, follow bool, stdout, stderr io.Writer) (err error) {
|
2014-08-27 19:41:32 +00:00
|
|
|
opts := docker.LogsOptions{
|
|
|
|
Container: containerID,
|
|
|
|
Stdout: true,
|
|
|
|
Stderr: true,
|
2014-09-22 20:14:23 +00:00
|
|
|
OutputStream: stdout,
|
|
|
|
ErrorStream: stderr,
|
2014-08-27 19:41:32 +00:00
|
|
|
Timestamps: true,
|
2014-11-12 10:42:55 +00:00
|
|
|
RawTerminal: false,
|
2014-09-15 16:20:01 +00:00
|
|
|
Follow: follow,
|
2014-08-27 19:41:32 +00:00
|
|
|
}
|
|
|
|
|
2014-09-15 16:20:01 +00:00
|
|
|
if !follow {
|
2014-08-27 19:41:32 +00:00
|
|
|
opts.Tail = tail
|
|
|
|
}
|
|
|
|
|
|
|
|
err = client.Logs(opts)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2014-10-03 06:39:02 +00:00
|
|
|
var (
|
|
|
|
// ErrNoContainersInPod is returned when there are no containers for a given pod
|
|
|
|
ErrNoContainersInPod = errors.New("no containers exist for this pod")
|
|
|
|
|
|
|
|
// ErrNoNetworkContainerInPod is returned when there is no network container for a given pod
|
2014-10-06 18:54:51 +00:00
|
|
|
ErrNoNetworkContainerInPod = errors.New("No network container exists for this pod")
|
2014-10-03 06:39:02 +00:00
|
|
|
|
|
|
|
// ErrContainerCannotRun is returned when a container is created, but cannot run properly
|
|
|
|
ErrContainerCannotRun = errors.New("Container cannot run")
|
|
|
|
)
|
|
|
|
|
2014-11-07 06:41:16 +00:00
|
|
|
func inspectContainer(client DockerInterface, dockerID, containerName, tPath string) (*api.ContainerStatus, error) {
|
2014-10-03 06:39:02 +00:00
|
|
|
inspectResult, err := client.InspectContainer(dockerID)
|
2014-11-07 06:41:16 +00:00
|
|
|
|
2014-10-03 06:39:02 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2014-09-16 20:21:04 +00:00
|
|
|
if inspectResult == nil {
|
|
|
|
// Why did we not get an error?
|
2014-10-03 06:39:02 +00:00
|
|
|
return &api.ContainerStatus{}, nil
|
2014-09-16 20:21:04 +00:00
|
|
|
}
|
|
|
|
|
2014-10-03 06:39:02 +00:00
|
|
|
glog.V(3).Infof("Container: %s [%s] inspect result %+v", *inspectResult)
|
2014-10-06 18:54:51 +00:00
|
|
|
containerStatus := api.ContainerStatus{
|
|
|
|
Image: inspectResult.Config.Image,
|
|
|
|
}
|
2014-09-16 20:21:04 +00:00
|
|
|
|
2014-10-03 23:25:54 +00:00
|
|
|
waiting := true
|
2014-09-16 20:21:04 +00:00
|
|
|
if inspectResult.State.Running {
|
2014-10-03 06:39:02 +00:00
|
|
|
containerStatus.State.Running = &api.ContainerStateRunning{
|
|
|
|
StartedAt: inspectResult.State.StartedAt,
|
|
|
|
}
|
|
|
|
if containerName == "net" && inspectResult.NetworkSettings != nil {
|
|
|
|
containerStatus.PodIP = inspectResult.NetworkSettings.IPAddress
|
|
|
|
}
|
|
|
|
waiting = false
|
|
|
|
} else if !inspectResult.State.FinishedAt.IsZero() {
|
|
|
|
// TODO(dchen1107): Integrate with event to provide a better reason
|
2014-09-16 20:21:04 +00:00
|
|
|
containerStatus.State.Termination = &api.ContainerStateTerminated{
|
2014-10-03 06:39:02 +00:00
|
|
|
ExitCode: inspectResult.State.ExitCode,
|
|
|
|
Reason: "",
|
|
|
|
StartedAt: inspectResult.State.StartedAt,
|
|
|
|
FinishedAt: inspectResult.State.FinishedAt,
|
2014-09-16 20:21:04 +00:00
|
|
|
}
|
2014-11-07 06:41:16 +00:00
|
|
|
if tPath != "" {
|
|
|
|
path, found := inspectResult.Volumes[tPath]
|
|
|
|
if found {
|
|
|
|
data, err := ioutil.ReadFile(path)
|
|
|
|
if err != nil {
|
|
|
|
glog.Errorf("Error on reading termination-log %s(%v)", path, err)
|
|
|
|
} else {
|
|
|
|
containerStatus.State.Termination.Message = string(data)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2014-10-03 06:39:02 +00:00
|
|
|
waiting = false
|
2014-09-16 20:21:04 +00:00
|
|
|
}
|
|
|
|
|
2014-10-03 06:39:02 +00:00
|
|
|
if waiting {
|
|
|
|
// TODO(dchen1107): Separate issue docker/docker#8294 was filed
|
|
|
|
// TODO(dchen1107): Need to figure out why we are still waiting
|
|
|
|
// Check any issue to run container
|
|
|
|
containerStatus.State.Waiting = &api.ContainerStateWaiting{
|
|
|
|
Reason: ErrContainerCannotRun.Error(),
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return &containerStatus, nil
|
|
|
|
}
|
2014-07-18 14:54:43 +00:00
|
|
|
|
2014-07-15 17:26:56 +00:00
|
|
|
// GetDockerPodInfo returns docker info for all containers in the pod/manifest.
|
2014-10-08 19:56:02 +00:00
|
|
|
func GetDockerPodInfo(client DockerInterface, manifest api.PodSpec, podFullName, uuid string) (api.PodInfo, error) {
|
2014-07-15 17:26:56 +00:00
|
|
|
info := api.PodInfo{}
|
2014-11-07 06:41:16 +00:00
|
|
|
expectedContainers := make(map[string]api.Container)
|
|
|
|
for _, container := range manifest.Containers {
|
|
|
|
expectedContainers[container.Name] = container
|
|
|
|
}
|
|
|
|
expectedContainers["net"] = api.Container{}
|
2014-07-15 17:26:56 +00:00
|
|
|
|
2014-09-10 20:20:29 +00:00
|
|
|
containers, err := client.ListContainers(docker.ListContainersOptions{All: true})
|
2014-07-15 17:26:56 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
for _, value := range containers {
|
2014-09-09 04:33:17 +00:00
|
|
|
dockerManifestID, dockerUUID, dockerContainerName, _ := ParseDockerName(value.Names[0])
|
2014-07-18 18:42:47 +00:00
|
|
|
if dockerManifestID != podFullName {
|
2014-07-15 17:26:56 +00:00
|
|
|
continue
|
|
|
|
}
|
2014-09-05 09:49:11 +00:00
|
|
|
if uuid != "" && dockerUUID != uuid {
|
|
|
|
continue
|
|
|
|
}
|
2014-11-07 06:41:16 +00:00
|
|
|
c, found := expectedContainers[dockerContainerName]
|
|
|
|
terminationMessagePath := ""
|
|
|
|
if !found {
|
|
|
|
// TODO(dchen1107): should figure out why not continue here
|
|
|
|
// continue
|
|
|
|
} else {
|
|
|
|
terminationMessagePath = c.TerminationMessagePath
|
|
|
|
}
|
2014-09-10 20:20:29 +00:00
|
|
|
// We assume docker return us a list of containers in time order
|
2014-09-16 20:21:04 +00:00
|
|
|
if containerStatus, found := info[dockerContainerName]; found {
|
|
|
|
containerStatus.RestartCount += 1
|
|
|
|
info[dockerContainerName] = containerStatus
|
2014-09-10 20:20:29 +00:00
|
|
|
continue
|
|
|
|
}
|
|
|
|
|
2014-11-07 06:41:16 +00:00
|
|
|
containerStatus, err := inspectContainer(client, value.ID, dockerContainerName, terminationMessagePath)
|
2014-07-15 17:26:56 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2014-10-03 06:39:02 +00:00
|
|
|
info[dockerContainerName] = *containerStatus
|
2014-07-15 17:26:56 +00:00
|
|
|
}
|
2014-10-03 06:39:02 +00:00
|
|
|
|
2014-07-18 14:54:43 +00:00
|
|
|
if len(info) == 0 {
|
|
|
|
return nil, ErrNoContainersInPod
|
|
|
|
}
|
|
|
|
|
2014-10-03 06:39:02 +00:00
|
|
|
// First make sure we are not missing network container
|
|
|
|
if _, found := info["net"]; !found {
|
|
|
|
return nil, ErrNoNetworkContainerInPod
|
|
|
|
}
|
|
|
|
|
|
|
|
if len(info) < (len(manifest.Containers) + 1) {
|
|
|
|
var containerStatus api.ContainerStatus
|
|
|
|
// Not all containers expected are created, verify if there are
|
|
|
|
// image related issues
|
|
|
|
for _, container := range manifest.Containers {
|
|
|
|
if _, found := info[container.Name]; found {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
|
|
|
|
image := container.Image
|
|
|
|
// Check image is ready on the node or not
|
|
|
|
// TODO(dchen1107): docker/docker/issues/8365 to figure out if the image exists
|
|
|
|
_, err := client.InspectImage(image)
|
2014-10-06 18:54:51 +00:00
|
|
|
if err == nil {
|
|
|
|
containerStatus.State.Waiting = &api.ContainerStateWaiting{
|
|
|
|
Reason: fmt.Sprintf("Image: %s is ready, container is creating", image),
|
|
|
|
}
|
|
|
|
} else if err == docker.ErrNoSuchImage {
|
|
|
|
containerStatus.State.Waiting = &api.ContainerStateWaiting{
|
|
|
|
Reason: fmt.Sprintf("Image: %s is not ready on the node", image),
|
2014-10-03 06:39:02 +00:00
|
|
|
}
|
|
|
|
} else {
|
2014-10-06 18:54:51 +00:00
|
|
|
containerStatus.State.Waiting = &api.ContainerStateWaiting{
|
|
|
|
Reason: err.Error(),
|
|
|
|
}
|
2014-10-03 06:39:02 +00:00
|
|
|
}
|
2014-10-06 18:54:51 +00:00
|
|
|
|
2014-10-03 06:39:02 +00:00
|
|
|
info[container.Name] = containerStatus
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2014-07-15 17:26:56 +00:00
|
|
|
return info, nil
|
|
|
|
}
|
|
|
|
|
2014-07-15 15:34:48 +00:00
|
|
|
const containerNamePrefix = "k8s"
|
|
|
|
|
2014-09-09 04:33:17 +00:00
|
|
|
func HashContainer(container *api.Container) uint64 {
|
2014-08-07 23:59:18 +00:00
|
|
|
hash := adler32.New()
|
|
|
|
fmt.Fprintf(hash, "%#v", *container)
|
|
|
|
return uint64(hash.Sum32())
|
|
|
|
}
|
|
|
|
|
2014-07-18 18:42:47 +00:00
|
|
|
// Creates a name which can be reversed to identify both full pod name and container name.
|
2014-09-09 04:33:17 +00:00
|
|
|
func BuildDockerName(manifestUUID, podFullName string, container *api.Container) string {
|
2014-09-25 00:05:53 +00:00
|
|
|
containerName := container.Name + "." + strconv.FormatUint(HashContainer(container), 16)
|
2014-07-15 15:34:48 +00:00
|
|
|
// Note, manifest.ID could be blank.
|
2014-09-09 04:33:17 +00:00
|
|
|
if len(manifestUUID) == 0 {
|
2014-09-25 00:05:53 +00:00
|
|
|
return fmt.Sprintf("%s_%s_%s_%08x",
|
2014-09-05 09:49:11 +00:00
|
|
|
containerNamePrefix,
|
|
|
|
containerName,
|
2014-09-25 00:05:53 +00:00
|
|
|
podFullName,
|
2014-09-05 09:49:11 +00:00
|
|
|
rand.Uint32())
|
|
|
|
} else {
|
2014-09-25 00:05:53 +00:00
|
|
|
return fmt.Sprintf("%s_%s_%s_%s_%08x",
|
2014-09-05 09:49:11 +00:00
|
|
|
containerNamePrefix,
|
|
|
|
containerName,
|
2014-09-25 00:05:53 +00:00
|
|
|
podFullName,
|
|
|
|
manifestUUID,
|
2014-09-05 09:49:11 +00:00
|
|
|
rand.Uint32())
|
|
|
|
}
|
2014-07-15 15:34:48 +00:00
|
|
|
}
|
|
|
|
|
2014-09-23 23:33:39 +00:00
|
|
|
// Unpacks a container name, returning the pod full name and container name we would have used to
|
|
|
|
// construct the docker name. If the docker name isn't the one we created, we may return empty strings.
|
2014-09-09 04:33:17 +00:00
|
|
|
func ParseDockerName(name string) (podFullName, uuid, containerName string, hash uint64) {
|
2014-07-15 15:34:48 +00:00
|
|
|
// For some reason docker appears to be appending '/' to names.
|
2014-07-28 13:56:03 +00:00
|
|
|
// If it's there, strip it.
|
2014-07-15 15:34:48 +00:00
|
|
|
if name[0] == '/' {
|
|
|
|
name = name[1:]
|
|
|
|
}
|
2014-09-25 00:05:53 +00:00
|
|
|
parts := strings.Split(name, "_")
|
2014-07-15 15:34:48 +00:00
|
|
|
if len(parts) == 0 || parts[0] != containerNamePrefix {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
if len(parts) > 1 {
|
2014-08-07 23:59:18 +00:00
|
|
|
pieces := strings.Split(parts[1], ".")
|
2014-09-25 00:05:53 +00:00
|
|
|
containerName = pieces[0]
|
2014-08-07 23:59:18 +00:00
|
|
|
if len(pieces) > 1 {
|
|
|
|
var err error
|
|
|
|
hash, err = strconv.ParseUint(pieces[1], 16, 32)
|
|
|
|
if err != nil {
|
2014-09-18 10:46:14 +00:00
|
|
|
glog.Warningf("invalid container hash: %s", pieces[1])
|
2014-08-07 23:59:18 +00:00
|
|
|
}
|
|
|
|
}
|
2014-07-15 15:34:48 +00:00
|
|
|
}
|
|
|
|
if len(parts) > 2 {
|
2014-09-25 00:05:53 +00:00
|
|
|
podFullName = parts[2]
|
2014-07-15 15:34:48 +00:00
|
|
|
}
|
2014-09-05 09:49:11 +00:00
|
|
|
if len(parts) > 4 {
|
2014-09-25 00:05:53 +00:00
|
|
|
uuid = parts[3]
|
2014-09-05 09:49:11 +00:00
|
|
|
}
|
2014-07-15 15:34:48 +00:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2014-07-20 17:31:26 +00:00
|
|
|
// Parses image name including a tag and returns image name and tag.
|
2014-09-05 09:49:11 +00:00
|
|
|
// TODO: Future Docker versions can parse the tag on daemon side, see
|
2014-07-15 15:34:48 +00:00
|
|
|
// https://github.com/dotcloud/docker/issues/6876
|
|
|
|
// So this can be deprecated at some point.
|
|
|
|
func parseImageName(image string) (string, string) {
|
|
|
|
tag := ""
|
|
|
|
parts := strings.SplitN(image, "/", 2)
|
|
|
|
repo := ""
|
|
|
|
if len(parts) == 2 {
|
|
|
|
repo = parts[0]
|
|
|
|
image = parts[1]
|
|
|
|
}
|
|
|
|
parts = strings.SplitN(image, ":", 2)
|
|
|
|
if len(parts) == 2 {
|
|
|
|
image = parts[0]
|
|
|
|
tag = parts[1]
|
|
|
|
}
|
|
|
|
if repo != "" {
|
|
|
|
image = fmt.Sprintf("%s/%s", repo, image)
|
|
|
|
}
|
|
|
|
return image, tag
|
|
|
|
}
|
2014-09-09 04:33:17 +00:00
|
|
|
|
|
|
|
type ContainerCommandRunner interface {
|
|
|
|
RunInContainer(containerID string, cmd []string) ([]byte, error)
|
|
|
|
}
|
2014-09-06 01:13:19 +00:00
|
|
|
|
|
|
|
// dockerKeyring tracks a set of docker registry credentials, maintaining a
|
|
|
|
// reverse index across the registry endpoints. A registry endpoint is made
|
|
|
|
// up of a host (e.g. registry.example.com), but it may also contain a path
|
|
|
|
// (e.g. registry.example.com/foo) This index is important for two reasons:
|
|
|
|
// - registry endpoints may overlap, and when this happens we must find the
|
|
|
|
// most specific match for a given image
|
|
|
|
// - iterating a map does not yield predictable results
|
|
|
|
type dockerKeyring struct {
|
|
|
|
index []string
|
|
|
|
creds map[string]docker.AuthConfiguration
|
|
|
|
}
|
|
|
|
|
|
|
|
func newDockerKeyring() *dockerKeyring {
|
|
|
|
return &dockerKeyring{
|
|
|
|
index: make([]string, 0),
|
|
|
|
creds: make(map[string]docker.AuthConfiguration),
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (dk *dockerKeyring) add(registry string, creds docker.AuthConfiguration) {
|
|
|
|
dk.creds[registry] = creds
|
|
|
|
|
|
|
|
dk.index = append(dk.index, registry)
|
|
|
|
dk.reindex()
|
|
|
|
}
|
|
|
|
|
|
|
|
// reindex updates the index used to identify which credentials to use for
|
|
|
|
// a given image. The index is reverse-sorted so more specific paths are
|
|
|
|
// matched first. For example, if for the given image "quay.io/coreos/etcd",
|
|
|
|
// credentials for "quay.io/coreos" should match before "quay.io".
|
|
|
|
func (dk *dockerKeyring) reindex() {
|
|
|
|
sort.Sort(sort.Reverse(sort.StringSlice(dk.index)))
|
|
|
|
}
|
|
|
|
|
2014-11-06 19:11:29 +00:00
|
|
|
const defaultRegistryHost = "index.docker.io/v1/"
|
|
|
|
|
2014-09-06 01:13:19 +00:00
|
|
|
func (dk *dockerKeyring) lookup(image string) (docker.AuthConfiguration, bool) {
|
|
|
|
// range over the index as iterating over a map does not provide
|
|
|
|
// a predictable ordering
|
|
|
|
for _, k := range dk.index {
|
|
|
|
if !strings.HasPrefix(image, k) {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
|
|
|
|
return dk.creds[k], true
|
|
|
|
}
|
|
|
|
|
2014-11-06 19:11:29 +00:00
|
|
|
// use credentials for the default registry if provided
|
|
|
|
if auth, ok := dk.creds[defaultRegistryHost]; ok {
|
|
|
|
return auth, true
|
|
|
|
}
|
|
|
|
|
2014-09-06 01:13:19 +00:00
|
|
|
return docker.AuthConfiguration{}, false
|
|
|
|
}
|
|
|
|
|
|
|
|
func (dk dockerKeyring) count() int {
|
|
|
|
return len(dk.creds)
|
|
|
|
}
|