Skip to content

fix: stop per-node pod watchers when nodes are deleted - #28

Open
gnuletik wants to merge 1 commit into
wish:masterfrom
gnuletik:fix/leak-per-node-pod-watchers
Open

gnuletik wants to merge 1 commit into
wish:masterfrom
gnuletik:fix/leak-per-node-pod-watchers

Conversation

@gnuletik

Copy link
Copy Markdown

The nodes informer only handled Add/Update, so when a node was deleted its per-node pod watcher was never torn down. Each leaked node kept a blocked goroutine, a running pod informer (with its own clientset and watch connection), and a podStore entry holding every cached pod. In an autoscaled cluster with churning nodes this grows unbounded (~10 MiB/day observed in prod).

Track each node's stop channel and add a DeleteFunc that closes it via a single stopNodeWatcher helper (close owned solely there, guarded by map membership under isHandling, so exactly-once).

Also fixed two related issues in the same path:

  • Reserve the podStore slot synchronously under the lock so a burst of node updates can't spawn two watchers for one node.
  • Log-and-clean instead of logrus.Fatalf on pod-informer creation failure; a Fatal in the goroutine took down the whole controller and left every node tainted.

The nodes informer only handled Add/Update, so when a node was deleted
its per-node pod watcher was never torn down. Each leaked node kept a
blocked goroutine, a running pod informer (with its own clientset and
watch connection), and a podStore entry holding every cached pod. In an
autoscaled cluster with churning nodes this grows unbounded (~10 MiB/day
observed in prod).

Track each node's stop channel and add a DeleteFunc that closes it via a
single stopNodeWatcher helper (close owned solely there, guarded by map
membership under isHandling, so exactly-once).

Also fixed two related issues in the same path:
- Reserve the podStore slot synchronously under the lock so a burst of
  node updates can't spawn two watchers for one node.
- Log-and-clean instead of logrus.Fatalf on pod-informer creation
  failure; a Fatal in the goroutine took down the whole controller and
  left every node tainted.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant