metal-stack / firewall-controller

A kubernetes controller running on bare-metal firewalls, creating nftables rules, configures suricata, collects network metrics
MIT License
47 stars 4 forks source link

Proposal: store DNS state in ConfigMap #130

Open GrigoriyMikhalkin opened 1 year ago

GrigoriyMikhalkin commented 1 year ago

At the moment we store DNS state in the CWNP status. DNS state is required to quickly restore nftables rules in case of machine reboot. Here is a response about Status field limit, which is limited only by etcd entry size(by default 1.5MB). So the there shouldn't be any restrictions to store the state in the object's Status.

Still, there's question if it can be optimized in terms of user experience. Aforementioned response proposes to use ConfigMap for storing big statuses. Which(potentially) can lead to some performance improvements. Also, Status intention is to show the operational state. And in our case it's used for caching. Moving caching to ConfigMap looks like a more "clean" solution.