fix(kind): validate the allocation response Agones actually returns

With the Fleet readiness wait corrected, the gate reached the allocation
check for the first time and failed with "allocation did not return a
GameServer" -- while the cluster dump shows the allocation plainly
succeeded: one GameServer Allocated, Fleet reporting ALLOCATED 1.

GameServerAllocationStatus is flat: state, gameServerName, address,
ports, nodeName. It does not embed the allocated GameServer. The
validator read status.gameServer.metadata.name and
status.gameServer.status.{address,ports}, a shape Agones never sends,
and its unit tests asserted that same invented shape -- so validator and
tests agreed with each other while both disagreed with Agones. Nothing
caught it because the gate had never once allocated anything.

Read the real fields, keeping every existing check: non-empty name,
address neither blank nor unspecified, exactly one named "game" port in
range.

Also print the response body when validation fails. work_dir is removed
by the EXIT trap, so a shape mismatch was otherwise invisible from CI --
which is how this survived. If the shape is still not what I expect, the
next run says so instead of costing another round trip.
This commit is contained in:
Josh Creek
2026-09-05 22:03:41 +01:00
parent 4f48f0a6a8
commit 52ee181042
3 changed files with 34 additions and 25 deletions
@@ -9,15 +9,15 @@ from verify_agones_allocation_response import validate_allocation
def response(**overrides): def response(**overrides):
document = { document = {
# Mirrors Agones' real GameServerAllocationStatus, which is flat.
# These fixtures previously encoded a nested "gameServer" object that
# Agones never returns, so the suite agreed with the validator while
# both disagreed with reality.
"status": { "status": {
"state": "Allocated", "state": "Allocated",
"gameServer": { "gameServerName": "cosmic-clash-game-abc",
"metadata": {"name": "cosmic-clash-game-abc"}, "address": "10.0.0.7",
"status": { "ports": [{"name": "game", "port": 31001}],
"address": "10.0.0.7",
"ports": [{"name": "game", "port": 31001}],
},
},
} }
} }
document["status"].update(overrides) document["status"].update(overrides)
@@ -34,28 +34,28 @@ class AgonesAllocationResponseTest(unittest.TestCase):
def test_rejects_missing_identity_or_address(self): def test_rejects_missing_identity_or_address(self):
missing_name = response() missing_name = response()
missing_name["status"]["gameServer"]["metadata"] = {} missing_name["status"]["gameServerName"] = ""
with self.assertRaises(ValueError): with self.assertRaises(ValueError):
validate_allocation(missing_name) validate_allocation(missing_name)
missing_address = response() missing_address = response()
missing_address["status"]["gameServer"]["status"]["address"] = "0.0.0.0" missing_address["status"]["address"] = "0.0.0.0"
with self.assertRaises(ValueError): with self.assertRaises(ValueError):
validate_allocation(missing_address) validate_allocation(missing_address)
def test_rejects_ambiguous_or_invalid_game_ports(self): def test_rejects_ambiguous_or_invalid_game_ports(self):
duplicate = response() duplicate = response()
duplicate["status"]["gameServer"]["status"]["ports"].append({"name": "game", "port": 31002}) duplicate["status"]["ports"].append({"name": "game", "port": 31002})
with self.assertRaises(ValueError): with self.assertRaises(ValueError):
validate_allocation(duplicate) validate_allocation(duplicate)
wrong_name = response() wrong_name = response()
wrong_name["status"]["gameServer"]["status"]["ports"] = [{"name": "query", "port": 31001}] wrong_name["status"]["ports"] = [{"name": "query", "port": 31001}]
with self.assertRaises(ValueError): with self.assertRaises(ValueError):
validate_allocation(wrong_name) validate_allocation(wrong_name)
invalid_port = response() invalid_port = response()
invalid_port["status"]["gameServer"]["status"]["ports"][0]["port"] = 70000 invalid_port["status"]["ports"][0]["port"] = 70000
with self.assertRaises(ValueError): with self.assertRaises(ValueError):
validate_allocation(invalid_port) validate_allocation(invalid_port)
+12 -12
View File
@@ -11,26 +11,26 @@ def validate_allocation(document: dict[str, Any]) -> tuple[str, int]:
if not isinstance(status, dict) or status.get("state") != "Allocated": if not isinstance(status, dict) or status.get("state") != "Allocated":
raise ValueError(f"allocation state is {status.get('state') if isinstance(status, dict) else None!r}, expected 'Allocated'") raise ValueError(f"allocation state is {status.get('state') if isinstance(status, dict) else None!r}, expected 'Allocated'")
game_server = status.get("gameServer") # GameServerAllocationStatus is flat: state, gameServerName, address,
if not isinstance(game_server, dict): # ports, nodeName. It does not embed the allocated GameServer object. This
raise ValueError("allocation did not return a GameServer") # validator originally read status.gameServer.metadata.name and
metadata = game_server.get("metadata") # status.gameServer.status.{address,ports}, and its tests asserted that
name = metadata.get("name") if isinstance(metadata, dict) else None # same invented shape, so both agreed with each other and neither agreed
# with Agones -- undetected because the gate never once got far enough to
# allocate anything.
name = status.get("gameServerName")
if not isinstance(name, str) or not name.strip(): if not isinstance(name, str) or not name.strip():
raise ValueError("allocation GameServer has no metadata.name") raise ValueError("allocation did not return a gameServerName")
game_status = game_server.get("status") address = status.get("address")
if not isinstance(game_status, dict):
raise ValueError("allocation GameServer has no status")
address = game_status.get("address")
if not isinstance(address, str) or not address.strip() or any(char.isspace() for char in address): if not isinstance(address, str) or not address.strip() or any(char.isspace() for char in address):
raise ValueError(f"allocation returned an invalid address: {address!r}") raise ValueError(f"allocation returned an invalid address: {address!r}")
if address in {"0.0.0.0", "::"}: if address in {"0.0.0.0", "::"}:
raise ValueError(f"allocation returned an unspecified address: {address!r}") raise ValueError(f"allocation returned an unspecified address: {address!r}")
ports = game_status.get("ports") ports = status.get("ports")
if not isinstance(ports, list): if not isinstance(ports, list):
raise ValueError("allocation GameServer has no ports") raise ValueError("allocation returned no ports")
game_ports = [ game_ports = [
entry.get("port") entry.get("port")
for entry in ports for entry in ports
+10 -1
View File
@@ -206,4 +206,13 @@ spec:
EOF EOF
kubectl create -f "$work_dir/allocation.yaml" -o json > "$work_dir/allocation.json" kubectl create -f "$work_dir/allocation.yaml" -o json > "$work_dir/allocation.json"
python3 scripts/verify_agones_allocation_response.py "$work_dir/allocation.json" # Print the response when validation fails. work_dir is deleted by the EXIT
# trap, so a mismatch between what Agones returns and what the validator
# expects is otherwise unknowable from CI -- which is exactly how a validator
# reading a field Agones never sends survived undetected.
if ! python3 scripts/verify_agones_allocation_response.py "$work_dir/allocation.json"; then
echo "--- allocation response as returned by Agones ---" >&2
cat "$work_dir/allocation.json" >&2 || true
echo >&2
exit 1
fi