Skip to content

Make the deploy/incus baseline and drift validator usable on a clustered Incus server #68

Description

@jmgilman

Problem

The controller runtime works against a clustered Incus server in HTTPS mode (#65/#66), but the deploy/incus/ baseline and the validate subcommand cannot be used on one:

  • deploy/incus/cue/deployment.cue pins server.standalone: true and server.cluster_https_address: "" as constants.
  • internal/incusvalidate/validator.go validateServer returns clustered Incus is outside this dedicated-host baseline when Standalone && actual.Clustered, and cluster.https_address must remain empty when the member's cluster.https_address differs from the (necessarily empty) baseline value.

Nothing in internal/runtime or internal/adapters/incus reads ServerClustered, so this is a baseline-shape limitation, not a runtime one. The result is that the drift validator — the second half of the deploy story — is unavailable exactly where HTTPS mode is most useful.

Observed on a 4-member IncusOS cluster running Incus 7.4 (source reading of v2.0.0; no live rejection was needed to confirm).

Proposal

Add a cluster server profile to the CUE deployment alongside the dedicated-host ones:

  • server.standalone: bool chosen by profile (false for the cluster profile).
  • server.cluster_https_address: for the cluster profile, a concrete host:port for the member the validator connects to (cluster.https_address is member-local, so the baseline describes the incus.url member).
  • validateServer drops the two hard-coded checks in favor of comparing against whatever the baseline says: standalone mismatch is still an error; cluster_https_address compares to the baseline value in both directions.
  • Re-verify firewall_driver and required_api_extensions against IncusOS (nftables) / Incus 7.4 and document any delta in the profile.

Out of scope: incus.target member placement for runner VMs (separate follow-up from #65); cluster-wide validation of every member (the validator connects to one member; say so in the docs).

Acceptance

  • deploy/incus/ renders a cluster-profile baseline; incus-gh-runner validate <baseline> --url … --client-cert-file … --server-cert-file … passes against a healthy cluster member and fails with a named reason on standalone, cluster.https_address, firewall driver, or extension drift.
  • Dedicated-host profiles unchanged and still reject a clustered server.
  • Docs: deploy/incus/README.md and how-to/deploy.md describe the cluster profile and its one-member scope.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions