Skip to content

fix(lb): keep only balancers and networks whose name matches exactly - #76

Open
lexfrei wants to merge 1 commit into
feat/cluster-name-prefixfrom
fix/match-balancer-name
Open

lexfrei wants to merge 1 commit into
feat/cluster-name-prefixfrom
fix/match-balancer-name

Conversation

@lexfrei

@lexfrei lexfrei commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

robotlb should only pick up a balancer or a network whose name is exactly the one it asked for. Today it passes the name as a filter to the Hetzner list endpoint and trusts the result. The API matches names exactly and case-sensitively, but it ignores an empty filter: GET /load_balancers?name= returns every balancer in the project, and GET /networks?name= returns every network.

So a Service annotated with robotlb/balancer: "" sees all balancers of the project as its own. With several of them, reconciliation fails as ambiguous. With a single unlabelled balancer on the same nodes, robotlb would adopt and reconfigure a balancer it never created. An empty network name has the same effect on a project with one network: the balancer gets attached to it.

The fix drops every listed item whose name is not the requested one before the result is used. The legacy-name lookup goes through the same code. Release never looks balancers up by name, so nothing changes there. With an empty balancer name robotlb now tries to create the balancer, Hetzner rejects the empty name, and the error shows up in the warning event. An empty network name fails as a network that was not found.

Unit tests cover the filter for both types. They keep the exact name and drop a case variant, a trailing space, a longer name and the full list returned for an empty name.

A test can't catch the filter being skipped at the two call sites, since they sit in async code that talks to Hetzner.

Stacked on #68.

The Hetzner API ignores an empty name filter: listing balancers or
networks with name= returns everything in the project. A service
annotated with an empty balancer name therefore saw every balancer as
a candidate. With several it failed as ambiguous, but with a single
unlabelled balancer on the same nodes it would adopt and reconfigure a
balancer it never created. An empty network name likewise attached
the balancer to the only network of the project.

Drop every listed balancer or network whose name is not exactly the
requested one. An empty name now matches nothing: robotlb goes on to
create the balancer and Hetzner rejects the empty name itself, and an
empty network name fails as a network that was not found.

Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <f@lex.la>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant