Skip to content

Build local service-route intent for VPC attachments - #634

Draft
scotwells wants to merge 3 commits into
mainfrom
feat/service-route-local-attachments
Draft

scotwells wants to merge 3 commits into
mainfrom
feat/service-route-local-attachments

Conversation

@scotwells

@scotwells scotwells commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Add Galactic’s first end-to-end ServiceRoutePolicy reconciliation path for node-local platform services.

Product impact

Shared services such as DNS64 can be reached from eligible VPC attachments without per-attachment or per-node Kubernetes resources. Galactic resolves the policy locally using Cloud API attachment state and programs the forward and return dataplane paths on the node.

Scope

  • Watch ServiceRoutePolicy, ServiceEndpoint, and Cloud VPCAttachment resources.
  • Use VPCAttachment.status.node as the authoritative placement field.
  • Evaluate selectors against local attachments.
  • Resolve consumer and service prefixes, VPCs, and host interfaces.
  • Compile deterministic local route intents.
  • Program bidirectional Linux VRF routes.
  • Program eBPF local pass-through entries in both VRFs.
  • Add cleanup and rollback behavior.
  • Add router RBAC for the internal APIs.
  • Add focused planner and attachment-index tests.

API dependency

ServiceEndpoint now supports an opaque reference to the Cloud API attachment that backs a private service endpoint. The matching API change is included in network PR #27.

Design constraints

  • No per-attachment child resources.
  • No per-node route resources.
  • No customer-facing DNS64-specific API.
  • ServiceRoutePolicy status remains conditions-only; operational counts belong in metrics.

Validation

go test ./internal/serviceroute

The broader Galactic suite requires the Linux build environment used by CI; this macOS workspace has existing netlink/eBPF build limitations.

@scotwells scotwells changed the title Index VPC attachments by observed node Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant