fix(proxy): bind D601 pod listener to local cni

This commit is contained in:
pikastech
2026-07-20 07:38:08 +02:00
parent cac3acb74f
commit cdb8e58c9b
2 changed files with 13 additions and 1 deletions
+10 -1
View File
@@ -46,6 +46,15 @@ sources:
nc01-vpn-server-shadowsocks:
extends: templates.sources.singBoxHostClient
benchmarkRef: local-vpn-server
d601-nc01-vpn-server-shadowsocks:
extends: templates.sources.singBoxHostClient
benchmarkRef: local-vpn-server
client:
podAccess:
enabled: true
listenHost: 10.42.1.1
listenPort: 10808
proxyUrl: http://10.42.1.1:10808
host-only-vpn-server-shadowsocks:
extends: templates.sources.singBoxHostClient
benchmarkRef: local-vpn-server
@@ -116,7 +125,7 @@ targets:
D601-VM:
extends: templates.targets.hostProxyClient
route: D601-VM
sourceRef: sources.nc01-vpn-server-shadowsocks
sourceRef: sources.d601-nc01-vpn-server-shadowsocks
files:
k3sSystemdDropIn: /etc/systemd/system/k3s-agent.service.d/10-unidesk-proxy.conf
env:
+3
View File
@@ -52,6 +52,9 @@
- 受控 apply 先比较声明态哈希,内容一致时跳过 `kubectl apply`,不得触发无意义 rollout。
- ServiceLB 只在 owning YAML 指定的公网节点启用,防止无公网地址 worker 接管 hostPort。
- worker 的 containerd 外网访问继承 host proxy systemd 环境,直接访问上游 registry;禁止为公共依赖新增 registry mirror。
- host proxy 的 Pod 访问监听地址必须由 owning YAML 按目标节点 PodCIDR
声明为该节点 `cni0` 地址;禁止复用其他节点的 `10.42.x.1`
否则 sing-box 会因绑定不存在地址持续重启。
- `127.0.0.1:5000` 只表示 UniDesk 集群内 artifact registryworker 的 `registries.yaml` 可把该本地引用映射到集群 endpoint,不得把它扩展为公共镜像代理。
- 幂等重复执行不得强写:
- WireGuard、systemd drop-in、agent unit、token 文件和节点标签均先比较声明态与运行态;