feat(bnk/cneinstance): auto-create F5BnkGateway chassis CR for AWS/EKS - #58
Closed
JLCode-tech wants to merge 1 commit into
Closed
JLCode-tech wants to merge 1 commit into
JLCode-tech wants to merge 1 commit into
Conversation
Encodes the recipe verified on aws-syd-test 2026-04-30 (see agent memory
project_aws_syd_test_tmm_kernelmode_break.md). Despite F5 docs saying
F5BnkGateway is optional, in f5ingress:v14.19.4-0.1.36 it's the trigger
that activates the entire Gateway translation pipeline on AWS/EKS.
Without it the controller logs "Watched application namespaces: []" and
silently ignores all Gateway+HTTPRoute CRs even when CNEInstance shows
Programmed=True.
New variable bnk_gateway_chassis (object: optional name +
default_listener_networks list of {name, start_address, end_address}).
Empty default_listener_networks = skip (preserves on-prem behavior).
Mirrors the existing null_resource.cloud_network_mapping pattern with
matching destroy provisioner.
DRAFT — needs fresh-cluster validation. Not yet tested against a
non-demo AWS deploy.
5 tasks
Owner
Author
|
Superseded by the new AWS catalog repo. The F5BnkGateway chassis auto-create logic is now part of Per the catalog repo migration, AWS-specific concerns live in the per-cloud catalog repo from now on. Closing this PR without merge — branch |
4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Despite F5 docs saying
F5BnkGatewayis optional, inf5ingress:v14.19.4-0.1.36it is the trigger that activates the entire Gateway translation pipeline on AWS/EKS. Without this CR, the controller logsWatched application namespaces: []and silently ignores allGateway+HTTPRouteCRs even when CNEInstance showsProgrammed=True. Discovery trail across 3 sessions is captured in the agent memory note.What changed
bnk/cneinstance/main.tf(+61) — newnull_resource.f5_bnkgateway_chassis. Mirrors the existingnull_resource.cloud_network_mappingpattern (gated count on input non-empty, matching destroy provisioner). Created invar.instance_namespace(controller's namespace).bnk/cneinstance/variables.tf(+28) — newbnk_gateway_chassisvariable (object: optionalnamedefaulting tobnk-gateway-chassis, plusdefault_listener_networkslist of{name, start_address, end_address}). Empty list = skip CR creation. Comments call out the explicit-address requirement (the CRD'sipv4BaseCidralternative is rejected by the controller runtime: "IPRange error: start/end IP addresses do not match IPv4 family").bnk/cneinstance/bnkforge.pack.json(+9) — register the new variable so forge's catalog CI gate (ci: validate every bnkforge.pack.json against forge contract #51) recognizes it.Verification recipe (when ready to promote from draft)
Apply the module to a fresh AWS/EKS cluster with:
Then deploy a
Gateway+HTTPRouteand verify:kubectl -n f5-operator get f5-bnkgatewaysshowsbnk-gateway-chassiswithProgrammed=Truekubectl -n f5-operator logs deploy/f5-cne-controller | grep "Watched application namespaces"shows[default](or your app ns), NOT[]curl http://<gateway-vip>/v1/...returns the actual backend response, not a TCP timeoutOut of scope (separate followup PRs)
infra/aws/cne-irsamodule — IRSA + allow-ec2-vip IAM policy (followup_cne_irsa_module.md)tmm-initConfigMap for static client/backend subnet routes (followup_tmm_init_routes_configmap.md)bnk-vlansENI fix —len(existing_enis) >= 3skip-guard ininfra/aws/high-performance-nodes/scripts/eni_attachment_manager.pyThese are tracked in agent memory followup notes for future PRs.
Backwards compat
Existing on-prem callers don't pass
bnk_gateway_chassis→ emptydefault_listener_networks→count = 0→ null_resource skipped → no behavior change. Only AWS/EKS callers that explicitly opt in see the new chassis CR creation.