%PDF- %PDF-
Mini Shell

Mini Shell

Direktori : /lib/python3/dist-packages/sos/collector/clusters/__pycache__/
Upload File :
Create Path :
Current File : //lib/python3/dist-packages/sos/collector/clusters/__pycache__/ocp.cpython-312.pyc

�

i��d@?��F�ddlZddlmZddlmZddlmZGd�de�Zy)�N)�quote)�Cluster)�
is_executablec���eZdZdZdZdZdZdZdZdZ	dZ
gd�Zed	��Z
d
�Zd�Z�fd�Zd
�Zd�Zd�Zd�Zd�Zd�Zd�Zd�Zd�Zd�Zd�Z�xZS)�ocpa�
    This profile is for use with OpenShift Container Platform (v4) clusters
    instead of the kubernetes profile.

    This profile will favor using the `oc` transport type, which means it will
    leverage a locally installed `oc` binary. This is also how node enumeration
    is done. To instead use SSH to connect to the nodes, use the
    '--transport=control_persist' option.

    Thus, a functional `oc` binary for the user executing sos collect is
    required. Functional meaning that the user can run `oc` commands with
    clusterAdmin privileges.

    If this requires the use of a secondary configuration file, specify that
    path with the 'kubeconfig' cluster option. This config file will also be
    used on a single master node to perform API collections if the `with-api`
    option is enabled (default disabled). If no `kubeconfig` option is given,
    but `with-api` is enabled, the cluster profile will attempt to use a
    well-known default kubeconfig file if it is available on the host.

    Alternatively, provide a clusterAdmin access token either via the 'token'
    cluster option or, preferably, the SOSOCPTOKEN environment variable.

    By default, this profile will enumerate only master nodes within the
    cluster, and this may be changed by overriding the 'role' cluster option.
    To collect from all nodes in the cluster regardless of role, use the form
    -c ocp.role=''.

    Filtering nodes by a label applied to that node is also possible via the
    label cluster option, though be aware that this is _combined_ with the role
    option mentioned above.

    To avoid redundant collections of OCP API information (e.g. 'oc get'
    commands), this profile will attempt to enable the API collections on only
    a single master node. If the none of the master nodes have a functional
    'oc' binary available, *and* the --no-local option is used, that means that
    no API data will be collected.
    zOpenShift Container Platform v4)zopenshift-hyperkubezopenshift-clientsFNzsos-collect-tmp�))�labelrz3Colon delimited list of labels to select nodes with)�role�masterz*Colon delimited list of roles to filter on)�
kubeconfigrzPath to the kubeconfig file)�tokenrz1Service account token to use for oc authorization)�with-apiFz'Collect OCP API data from a master nodec���|j�sPd|_|jjj�r�|jj	d|jjj
��}|ddk(rdtjj|jjj
|dj�jd��|_n(|jd�|jd	|dz�|jd
�r'|xjd|jd
�zz
c_|jd|jz�|jS)
N�oczwhich oc)�chroot�statusr�output�/zHUnable to to determine PATH for 'oc' command, node enumeration may fail.zLocating 'oc' failed: %srz --config %szoc base command set to %s)�_oc_cmd�primary�host�in_container�run_command�sysroot�os�path�join�strip�lstrip�log_warn�	log_debug�
get_option)�self�_oc_paths  �</usr/lib/python3/dist-packages/sos/collector/clusters/ocp.py�oc_cmdz
ocp.oc_cmdKs���|�|��D�L��|�|� � �-�-�/��<�<�3�3��t�|�|�'8�'8�'@�'@�4����H�%��*�#%�7�7�<�<����)�)�1�1� ��*�0�0�2�9�9�#�>�$�D�L�
�M�M�5���N�N�#=�%-�h�%7�$8�9����|�,���������1N� N�N���N�N�6����E�F��|�|��c�$�|j�d|��S)zcFormat the oc command to optionall include the kubeconfig file if
        one is specified
        � )r&)r#�cmds  r%�
fmt_oc_cmdzocp.fmt_oc_cmdds���+�+�s�+�+r'c�l�|j|jd|jz��}|ddk(S)zXAttempt to login to the API using the oc command using a provided
        token
        z0login --insecure-skip-tls-verify=True --token=%srr)�exec_primary_cmdr+r
)r#�_ress  r%�_attempt_oc_loginzocp._attempt_oc_loginjs@���$�$��O�O�N�"�j�j�)�
*�
���H�~��"�"r'c���tt|��ry|jd�xst	j
dd�|_|jr|j�|jd�}|j|�ddk(S)NTr
�SOSOCPTOKEN�whoamirr)
�superr�
check_enabledr"r�getenvr
r/r+r-)r#�_who�	__class__s  �r%r4zocp.check_enabledtso�����d�)�+���_�_�W�-�O����=�$�1O��
��:�:��"�"�$����x�(���$�$�T�*�8�4��9�9r'c���|j�dk(sy|j|jd��}|ddk(|_|js|j	d�td��|j
d|jz�|j|jd	|jz��}|ddk(r|j�y
|j	d|dz�td
��)zpCreate the project that we will be executing in for any nodes'
        collection via a container image
        rNzauth can-i '*' '*'rrzWCheck for cluster-admin privileges returned false, cannot create project in OCP clusterzLInsufficient permissions to create temporary collection project.
Aborting...z#Creating new temporary project '%s'znew-project %sTzFailed to create project: %srz?Failed to create temporary project for collection. 
Aborting...)	�set_transport_typer-r+�oc_cluster_adminr!�	Exception�log_info�project�_label_sos_project)r#�out�rets   r%�setupz	ocp.setup}s����&�&�(�D�0���#�#�D�O�O�4H�$I�J�� #�H�
�� 2����$�$��N�N�C�
D��?�@�
@�	
�
�
�;�d�l�l�J�K��#�#��O�O�,�t�|�|�;�<�
���x�=�A���#�#�%�����5��H�
�E�F��(�)�	)r'c
��ddg}|D]L}|j|jd|j�d|�d���}|ddk(r�=td|d	����y
)z�Add pertinent labels to the temporary project we've created so that
        our privileged containers can properly run.
        z4security.openshift.io/scc.podSecurityLabelSync=falsez-pod-security.kubernetes.io/enforce=privilegedzlabel namespace r)z --overwriterrz!Error applying namespace labels: rN)r-r+r=r;)r#�labelsr	r@s    r%r>zocp._label_sos_project�s~��

C�;�
���		�E��'�'����&�t�|�|�n�A�e�W�L�I���C�
�x�=�A�%��7��H�
��G���		r'c��|jr�	|j|jd|j���d��}|ddk(s|jd|d���|j|jd|j�d	���}|ddk(s|jd
|d���|j|jd��d
|_y#t$r}|jd|�d��Yd
}~�Kd
}~wwxYw)z8Remove the project we created to execute within
        zdelete project �)�timeoutrrz"Error deleting temporary project: rzwait namespace/z --for=delete --timeout=30sz3Error waiting for temporary project to be deleted: zAFailed attempting to remove temporary project 'sos-collect-tmp': z.
Please manually remove the temporary project.Nzproject defaultT)r=r-r+�	log_errorr;)r#r@�errs   r%�cleanupzocp.cleanup�s"���<�<�
��+�+��O�O�o�d�l�l�^�$D�E��,����8�}��)��N�N�<�S��]�O�L���+�+��O�O�)�$�,�,��8(�)�����8�}��)��N�N�M��x�=�/�+��
�!�!�$�/�/�2C�"D�E��D�L����
����*�*-��/D�E����
�s�BC�	C9�C4�4C9c�:�i}d|dvr�|jd�j�}i}dD]%}	|j|j��||<�'|D]2}|j�}i||d<|D]}|||||d|<��4|S#t$rY�lwxYw)a�From the output of get_nodes(), construct an easier-to-reference
        dict of nodes that will be used in determining labels, primary status,
        etc...

        :param nodelist:        The split output of `oc get nodes`
        :type nodelist:         ``list``

        :returns:           A dict of nodes with `get nodes` columns as keys
        :rtype:             ``dict``
        �NAMEr)r�roles�versionzos-image)�pop�split�index�upperr;)	r#�nodelist�nodes�statline�idx�state�node�_node�columns	         r%�_build_dictzocp._build_dict�s������X�a�[� ��|�|�A��,�,�.�H��C�C�
���!)������
�!>�C��J�
�
!�
A���
�
���"$��e�A�h��!�A�F�.3�C��K�.@�E�%��(�O�F�+�A�
A�
���!����s�"B�	B�Bc�T�|jjdk7r|jjStd|jjj
��ry|j
d�|jjd�|jjstd�y)N�autor)rz]Local installation of 'oc' not found or is not correctly configured. Will use ControlPersist.z=Preferred transport 'oc' not available, will fallback to SSH.z?Press ENTER to continue connecting with SSH, or Ctrl+C toabort.�control_persist)�opts�	transportrrrrr<�ui_log�warn�batch�input)r#s r%r9zocp.set_transport_type�s����9�9���&�(��9�9�&�&�&���t�|�|�'8�'8�'@�'@�A���
�
�G�	H������K�	
��y�y�����
� r'c���g}i|_d}|jd�r@dj|jd�jd��}|dt	|�zz
}|j|j
|��}|ddk(r�|jd�d	k(r|jd
�|jd�jd�D�cgc]}|��}}|j|dj��|_|jj�D]:\}}|r"|D]}	|	|dvs�|j|��(�*|j|��<|Sd
}
d|dvrd}
t|
��cc}w)Nzget nodes -o wider	�,�:z -l %srrr
rz�NOTE: By default, only master nodes are listed.
To collect from all/more nodes, override the role option with '-c ocp.role=role1:role2'rrLz'oc' command failedzMissing or incompleteza'oc' failed due to missing kubeconfig on primary node. Specify one via '-c ocp.kubeconfig=<path>')
�	node_dictr"rrOrr-r+r rZ�
splitlines�items�appendr;)r#rSr*rC�res�rrL�	node_namerWr
�msgs           r%�	get_nodesz
ocp.get_nodes�sr�������!���?�?�7�#��X�X�d�o�o�g�6�<�<�S�A�B�F��8�e�F�m�+�+�C��#�#�D�O�O�C�$8�9���x�=�A�����v�&�(�2��
�
�K�L�!%���� 7� =� =�c� B�C�1�Q�C�E�C�!�-�-�c�(�m�.F�.F�.H�I�D�N�#'�>�>�#7�#7�#9�
,��	�4�� %�"���4��=�0�!�L�L��3�!�"�
�L�L��+�
,���(�C�&�#�h�-�7�E���C�.� ��Ds�	E-c��|j|jvrydD]$}||j|jdvs�"|cSy)Nr)r�workerrL��addressrg)r#rWr	s   r%�set_node_labelzocp.set_node_labelsH���<�<�t�~�~�-��)�	�E�����t�|�|�4�W�=�=���	�r'c�p�|j|jvryd|j|jdvS)NFrrLrr)r#�sosnodes  r%�check_node_is_primaryzocp.check_node_is_primary s2���?�?�$�.�.�0���4�>�>�'�/�/�:�7�C�C�Cr'c��|jd�r	d}|rdnd}nd}|rdnd}|jjd|�d|���y)	a�In earlier versions of sos, the openshift plugin option that is
        used to toggle the API collections was called `no-oc` rather than
        `with-api`. This older plugin option had the inverse logic of the
        current `with-api` option.

        Use this to toggle the correct plugin option given the node's sos
        version. Note that the use of version 4.2 here is tied to the RHEL
        release (the only usecase for this cluster profile) rather than
        the upstream version given the backports for that downstream.

        :param node:    The node being inspected for API collections
        :type node:     ``SoSNode``

        :param use_api: Should this node enable API collections?
        :type use_api:  ``bool``
        z4.2-16r�on�offzno-ocz
openshift.�=N)�check_sos_version�plugoptsrj)r#rW�use_api�_opt�_vals     r%�_toggle_api_optzocp._toggle_api_opt%sE��"�!�!�(�+��D�"�4��D��D�#�5��D��
�
���$��=�>r'c���|jjd�|jd�s|j|d�y|jr|j|d�yd}|jd�}|r|jd�sd|z}|xs|}d}|jjrd	}|jd
d��r|d
z
}|jd|z|jjd��}|ddk(r|j|d�d|_n�|jr3|j|jd<|j|d�d|_nM|j|�r<||k(s|jjd|z�|j|d�d|_|jrFd|jz}|jj|�|j j|�yy)N�	openshiftrFzl/host/etc/kubernetes/static-pod-resources/kube-apiserver-certs/secrets/node-kubeconfigs/localhost.kubeconfigrz/hostz/host/rz/host/bin/ocz/root/.kube/configT)�	need_rootz% --kubeconfig /host/root/.kube/configz	%s whoami)�
use_containerr�rrr1zopenshift.kubeconfig=%szcAPI collections will be performed on %s
Note: API collections may extend runtime by 10s of minutes
)�enable_pluginsrjr"r��api_collect_enabled�
startswithr�
containerized�file_existsrr
�sos_env_varsr}rs�soslog�infor`)r#rW�master_kube�
_optconfig�_kubeconfigr�can_ocrns        r%�set_primary_optionszocp.set_primary_options>s������"�"�;�/����z�*�� � ��u�-���#�#�
� � ��u�-�'�
�
����6�J��*�"7�"7��"@�%�
�2�
�$�3��K��G��y�y�&�&�(���#�#�$8�D�#�I��F�F�G��%�%�k�G�&;�48�I�I�4K�4K�15�&�6�F��h��1�$��$�$�T�4�0�+/��(����37�:�:��!�!�-�0��$�$�T�4�0�+/��(��!�!�+�.�#�k�1��M�M�(�(�1�K�?���$�$�T�4�0�+/��(��'�'�L����&����� � ��%���� � ��%�(r'c�(�|j|d�y)NF)r�)r#rWs  r%�set_node_optionszocp.set_node_options{s�����T�5�)r')�__name__�
__module__�__qualname__�__doc__�cluster_name�packagesr�r
r=r:r�option_list�propertyr&r+r/r4rAr>rIrZr9rortrwr�r�r��
__classcell__)r7s@r%rrs����%�N5�L�;�H����E��G����G��K�����0,�#�:�)�6�&!�F�8
!��>�D�
?�2;&�z*r'r)r�pipesr�sos.collector.clustersr�
sos.utilitiesrr�r'r%�<module>r�s!��
��*�'�k*�'�k*r'

Zerion Mini Shell 1.0