Skip to content

feat: add node_readiness_rules with enforcement_mode and dry_run labels - #448

Merged
kubernetes-prow[bot] merged 2 commits into
kubernetes-sigs:mainfrom
rawadhossain:readiness-rules
Sep 20, 2026
Merged

kubernetes-prow[bot] merged 2 commits into
kubernetes-sigs:mainfrom
rawadhossain:readiness-rules

Conversation

@rawadhossain

@rawadhossain rawadhossain commented Aug 24, 2026 •

Copy link
Copy Markdown
Member

Description

  • Adds node_readiness_rules{enforcement_mode, dry_run} while keeping node_readiness_rules_total unchanged for compatibility.
  • Serves node_readiness_rules from the scrape-time ReadinessCollector. the original ruleCache push approach showed staleness scaling with rule count under bulk changes
  • Updates monitoring.md and docs/TEST_README.md.
  • Adds related tests, also contributes to testing: Add Test Coverage for Prometheus Metrics #269.

from the design doc:

image image

Related to #446

Type of Change

/kind feature

Testing

make test, make lint, go vet, gofmt -l all pass.

Checklist

  • make test passes
  • make lint passes

@kubernetes-prow kubernetes-prow Bot added the kind/feature Categorizes issue or PR as related to a new feature. label Aug 24, 2026
@kubernetes-prow
kubernetes-prow Bot requested review from mrunalp and tallclair August 24, 2026 08:19
@kubernetes-prow kubernetes-prow Bot added the cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. label Aug 24, 2026
@netlify

netlify Bot commented Aug 24, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for node-readiness-controller canceled.

Name Link
🔨 Latest commit 4dc8a70
🔍 Latest deploy log https://app.netlify.com/projects/node-readiness-controller/deploys/6aaf229bb15dfa0008e22890

@kubernetes-prow

Copy link
Copy Markdown

Hi @rawadhossain. Thanks for your PR.

I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Tip

We noticed you've done this a few times! Consider joining the org to skip this step and gain /lgtm and other bot rights. We recommend asking approvers on your previous PRs to sponsor you.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@kubernetes-prow kubernetes-prow Bot added needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Aug 24, 2026
@rawadhossain rawadhossain mentioned this pull request Aug 24, 2026
6 of 7 tasks
@rawadhossain

Copy link
Copy Markdown
Member Author

/cc @ajaysundark

@kubernetes-prow
kubernetes-prow Bot requested a review from ajaysundark August 26, 2026 08:19
@rawadhossain

Copy link
Copy Markdown
Member Author

/cc @AvineshTripathi

@AvineshTripathi

Copy link
Copy Markdown
Contributor

/ok-to-test

@kubernetes-prow kubernetes-prow Bot added ok-to-test Indicates a non-member PR verified by an org member that is safe to test. and removed needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Aug 29, 2026
@rawadhossain

Copy link
Copy Markdown
Member Author

/retest

@AvineshTripathi AvineshTripathi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since we're already calling ListRules in the collector, we can compute the enforcement_mode/dry_run breakdown there instead of maintaining a separate in-memory sync. The local ruleCache can lag behind actual cluster state and can be unreliable.

cc @ajaysundark wdyt?

@rawadhossain

rawadhossain commented Sep 1, 2026 •

Copy link
Copy Markdown
Member Author

@AvineshTripathi Good point. I tested both ways and found ruleCache can be stale on startup (~200-300ms) and for ~1s after creating a rule, and ListRules reflects the current state right away. The stale window is relatively small, so I think keeping the current approach is reasonable for now.

@ajaysundark since this metric wasn't part of the collector scope, should we switch or keep it separate for now?

@kubernetes-prow kubernetes-prow Bot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Sep 3, 2026
Signed-off-by: Rawad Hossain <rawad.hossain00@gmail.com>
@kubernetes-prow kubernetes-prow Bot removed the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Sep 3, 2026
@AvineshTripathi

Copy link
Copy Markdown
Contributor

The stale window is relatively small, so I think keeping the current approach is reasonable for now.

I would prefer testing this delay on the scale before doing the scale. Can we run the scan?

@rawadhossain

Copy link
Copy Markdown
Member Author

Yes we can and thanks it helped.

Ran the scale test. Used the test/scale setup. So here’s the findings:

ruleCache staleness (current one):

Scenario N=100 N=1000 N=5000
One rule changes ~130ms ~135ms ~145ms
One rule gets created ~1.15s ~1.15s ~1.2s
All N rules created at once ~2s ~14s ~79s
All N rules dryRun flipped at once ~1.5s ~11s ~62s
All N rules deleted at once ~1s ~11s ~57s

Single changes are fine, but bigger difference shows up when a large number of rules change together, delay grows quite long.

Scrape-time approach:

N 100 1000 5000
Standalone lookup ~0.37ms ~4.1ms ~23ms
Added to existing collector ~3µs ~26µs ~128µs

Since the collector already does that fetch, adding this one on barely adds anything.

Based on these, would it make more sense to go with collector instead, specially for scale? Staleness gets pretty noticeable with bulk changes, also extra cost in the collector is very small.

@AvineshTripathi @ajaysundark wdyt? I can make the changes if we decide to go with collector approach.

@AvineshTripathi

Copy link
Copy Markdown
Contributor

@rawadhossain I'll go with the collector approach! that can be a standard we can go for

@rawadhossain

Copy link
Copy Markdown
Member Author

@AvineshTripathi I also think so collector approach is the one to go for. Made the changes. Tested and everything's working as expected.
PTAL. Thanks!

cc @ajaysundark

@AvineshTripathi

Copy link
Copy Markdown
Contributor

/lgtm

havn't tested in local but looks good!

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Sep 18, 2026

@ajaysundark ajaysundark left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

Comment thread docs/book/src/operations/monitoring.md
Comment thread docs/book/src/operations/monitoring.md Outdated
@kubernetes-prow kubernetes-prow Bot removed the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Sep 19, 2026
@ajaysundark

Copy link
Copy Markdown
Contributor

/lgtm
/approve

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Sep 20, 2026
@kubernetes-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: ajaysundark, rawadhossain

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Sep 20, 2026
@kubernetes-prow
kubernetes-prow Bot merged commit f98c63f into kubernetes-sigs:main Sep 20, 2026
11 checks passed
@rawadhossain rawadhossain mentioned this pull request Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. kind/feature Categorizes issue or PR as related to a new feature. lgtm "Looks good to me", indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants