Skip to content

feature: let the api delete Kubernetes nodes of removed game server nodes - #638

Merged
lukepolo merged 1 commit into
mainfrom
feature/node-removal-cleanup
Oct 2, 2026
Merged

lukepolo merged 1 commit into
mainfrom
feature/node-removal-cleanup

Conversation

@Flegma

@Flegma Flegma commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Problem

Removing a game server node in the panel only deletes its game_server_nodes row. The Kubernetes objects the api created for that node stay behind: its update jobs, any game-streamer job that was pinned to it (which keeps its Steam account claimed), its volume claims and volume records, and its NotReady Node entry.

Fix

5stackgg/api#471 adds a cleanup for removed nodes. It runs automatically when a node row is deleted, and admins can also start it from Settings > Application > Servers (5stackgg/web#648).

This PR adds the delete verb on nodes to the api ClusterRole (server-creator-clusterrole), so the cleanup can also remove the Node entry of a removed node. Jobs and volume claims already have delete in the namespaced Role, and volume records already have delete in this ClusterRole.

Scope / notes

  • Privilege increase: the api service account can now delete any Node object in the cluster. The api only deletes the Node of a node id that has no game_server_nodes row and has been NotReady for at least 10 minutes. It never deletes a control plane node.
  • The Node goes first. Once it is gone, k8s deletes the pods it still lists, so the claims and volume records those pods hold can finish deleting.
  • Deploy order does not matter, but nodes removed in between need one manual run. Without this PR, the api gets a 403 on the Node delete and logs a warning. It still deletes the node's jobs, but keeps its Node entry, volume claims and volume records, because the pods on the Node would keep them terminating. The automatic cleanup does not try again, so after deploying this PR, run the cleanup under Settings > Application > Servers once for nodes removed before it. In the other order, nodes removed before the api update need that same run.
  • Apply it with the update script. The ClusterRole only lands through git pull && ./update.sh. The in-app Update only restarts the services, so until the script runs, the api keeps getting a 403 on the Node delete.
  • No other RBAC change.

…odes

The api cleanup of removed game server nodes deletes their NotReady
Node entry, so the api ClusterRole needs the delete verb on nodes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants