Repository navigation
Remove Orbit remote management - #6320
Conversation
Hello francoisferrand,My role is to assist you with the merge of this Available options
Available commands
Status report is not available. |
Waiting for approvalThe following approvals are needed before I can proceed with the merge:
|
Codecov Report❌ Patch coverage is
Additional details and impacted files
... and 1 file with indirect coverage changes @@ Coverage Diff @@
## development/9.5 #6320 +/- ##
===================================================
+ Coverage 86.55% 87.72% +1.16%
===================================================
Files 213 206 -7
Lines 14612 14196 -416
===================================================
- Hits 12647 12453 -194
+ Misses 1965 1743 -222
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
9cfb3ef to
d4a05f9
Compare
d4a05f9 to
d33c868
Compare
d33c868 to
4ffd418
Compare
69ad44b to
e96c785
Compare
|
Sounds like too many test failures to be flaky 🤔 |
Remote management (cloudserver connecting to Orbit to fetch its instance credentials, and polling or receiving configuration overlays that it applied and saved in the PENSIEVE bucket) has been dead for a long time: zenko-operator sets REMOTE_MANAGEMENT_DISABLE and renders locationConfig.json itself, Orbit / Zenko 1.x are no longer supported, and S3C never used it. Keeping it around only forces Arsenal to keep exporting the pensieve credential utils and patchLocations. This drops the management init in the server and the management agent, with the Orbit credentials, polling and overlay code they relied on. The zenko-instance-id user metadata goes too, as its value only ever came from an overlay. The push client still used by the metrics server and secure channel proxy now ignores overlay messages, and keeps handling metrics requests and channel data as before. overlayVersion is kept and still reported in /_/report: zenko-operator renders it in config.json and pensieve-api reads it from the report. The management config unit test happened to reset config.locationConstraints between suites, which was masking a leak in objectReplicationMD.js (it replaced the real awsbackend location and then deleted it). That test now restores the original entries. Issue: CLDSRV-1013
arsenal 8.6.0-preview.4 drops the pensieve and patches exports that cloudserver no longer uses. utapi now shares the same arsenal instead of carrying its own preview.1 copy. Issue: CLDSRV-1013
Re-resolve dependencies within their existing ranges. Issue: CLDSRV-1013
request is only pulled in by utapi (via oas-tools) and still asks for form-data ~2.3.2, which has a critical advisory. utapi already forces form-data ^2.5.6 under request, but yarn ignores resolutions from dependencies, so mirror it here: https://github.com/scality/utapi/blob/8.4.0/package.json#L61-L64 Issue: CLDSRV-1013
The push client could also tunnel raw S3 traffic from the push server to cloudserver over the websocket: this is how the Orbit browser reached S3 inside a deployment, through bin/secure_channel_proxy.js. Nothing else uses it, and zenko-operator stops deploying the proxy (ZKOP-617), so drop the script, the channel payload/close handling and the browserAccessEnabled toggle that was only set from an overlay. The push client is now only used by the metrics server, and only answers metrics requests. Issue: CLDSRV-1013
e96c785 to
1f97035
Compare
arsenal 8.6.0-preview.4 broke the file metadata backend: batch operations without a type are rejected since the classic-level migration, so the S3 server fails to start. scubaclient 1.2.1 moves to axios 1.20, which fixes quite a few more CVEs. Issue: CLDSRV-1013
Issue: CDSRV-1013
1f97035 to
f4110a3
Compare
|
/approve |
|
I have successfully merged the changeset of this pull request
The following branches have NOT changed:
This pull request did not target the following hotfix branch(es) so they
Please check the status of the associated issue CLDSRV-1013. Goodbye francoisferrand. The following options are set: approve |
Remote management means cloudserver connecting to Orbit/pensieve-api to fetch its instance credentials, then polling or receiving configuration overlays and applying and saving them in the
PENSIEVEmetadata bucket. That has been dead for a long time.Keeping the code around only forces Arsenal to keep exporting
pensieve.credentialUtilsandpatches.locationConstraints.What goes away:
managementAgent.js,managementAgentconfig,management_agentscript) andnode-forge.lib/management/{index,credentials,poll,configuration,agentClient}.js).bin/secure_channel_proxy.jsand the channel payload/close handling in the push client. It only tunnelled Orbit browser access to S3, and zenko-operator stops deploying it in ZKOP-617.The push client used by
metrics_serverstays (it now only answers metrics requests), as doesoverlayVersionin/_/report, which zenko-operator renders and pensieve-api reads.The PR also bumps arsenal to 8.6.0-preview.4, which no longer has the pensieve/patches exports, and cloudserverclient to 1.0.13. The lockfile was refreshed: utapi now shares the same arsenal, aws-sdk is deduplicated, and shell-quote is 1.12.0. A
**/request/form-dataresolution mirrors utapi's own, to get rid of the critical form-data advisory.Issue: CLDSRV-1013