chore(k8s): 下线 K8s 后端形态,移除依赖 @kubernetes/client-node

生产形态是单机 local(DEFAULT_DEPLOY_MODE=local,env 未覆盖)⇒ K8s 分支
在 local 下本来不可达;且该形态与官方 dsh 基座、插件体系均无关
=> 整体下线,并移除该形态唯一的第三方依赖。

移除(备份在 D:/github/_dsh_shenxian_K8s后端备份_20260915/,含还原命令与
「集群化方案要复用的模板清单」):
  src/supervisor/{k8s-spawner,leader,reconcile}.ts
  src/fs/k8s-user-fs.ts · src/tcp-bridge.ts · src/web/file-service.ts
  test/{k8s-spawner,leader}.test.mjs · scripts/smoke-file-service.mjs

改写调用方:cli.ts(5 条 import / 选主块 / file-service 与 tcp-bridge 两个
子命令 / dispatch / HELP)、web/server.ts(改为 fail-loud 守卫 + 恒用
LocalSpawner)、fs/provider.ts(只留 LocalUserFs)、package.json(测试与
smoke 入口),外加 3 处指向已删类型的悬空 JSDoc。

保留(集群化方案列为未来可选):deploy/ · poc/01-04 · Dockerfile.dsh ·
docs/k8s*.md(已加「代码已下线」状态横幅)· config.ts 的 K8s 配置字段与
DeployMode 联合类型。

验证:tsc --noEmit exit 0;npm test 36 测试 / 35 通过 / 0 失败 / 1 跳过;
npm run verify exit 0;依赖与被删符号全仓 0 命中。
This commit is contained in:
admin committed 2026-09-15 06:36:20 +08:00
1 parent ed0c3c0ad5
commit cf8b7b1f5c
19 files changed
+29 -2690

No files matched your search

-72
View File
@@ -4,7 +4,6 @@
*
* Subcommands:
* dshs bootstrap-admin --username <u> --password <p>
* dshs file-service per-user file sidecar (k8s)
* dshs [server flags]
* @module dshs/cli
*/
@@ -17,11 +16,6 @@ import { createUserFs } from './fs/provider.js'
import { homeRoot, userRoot } from './fs/workspace.js'
import { hashPassword } from './web/auth.js'
import { hashUid } from './isolation.js'
import { LeaderElector } from './supervisor/leader.js'
import { ReconcileController } from './supervisor/reconcile.js'
import { K8sSpawner } from './supervisor/k8s-spawner.js'
import { buildFileService, FILE_SERVICE_PORT, USER_ROOT_ENV } from './web/file-service.js'
import { startTcpBridge } from './tcp-bridge.js'
import { buildServer } from './web/server.js'
const HELP = `dshs — DSH server login orchestrator
@@ -29,7 +23,6 @@ const HELP = `dshs — DSH server login orchestrator
Usage:
dshs [options] start the server
dshs bootstrap-admin [options] create the first admin
dshs file-service run the per-user file sidecar
Server options:
--port <n> Bind port (0 = ephemeral). Default 3080.
@@ -138,47 +131,6 @@ async function runServer(args: string[]): Promise<void> {
app.log.info(`dshs listening on http://${config.host}:${actualPort}`)
app.log.info(`data root: ${config.dataRoot}; db: ${config.dbPath}`)
// In k8s mode, only the elected leader runs the controller (reconcile + Pod
// watch). The web layer serves on every replica.
let controller: ReconcileController | undefined
if (config.deployMode === 'k8s') {
const spawner = app.supervisor as K8sSpawner
const elector = new LeaderElector({ namespace: config.k8sNamespace, identity: config.podName })
controller = new ReconcileController(app.db, spawner, elector)
await controller.start()
app.log.info(`leader election started (identity ${config.podName})`)
}
const shutdown = async (signal: string): Promise<void> => {
app.log.info(`received ${signal}, shutting down`)
controller?.stop()
await app.close()
process.exit(0)
}
process.on('SIGINT', () => void shutdown('SIGINT'))
process.on('SIGTERM', () => void shutdown('SIGTERM'))
}
/**
* Run the per-user file sidecar. Serves one user's volume over HTTP on 8082 so
* the control plane (which holds no users volume under k8s) can reach it; the
* root comes from the Pod's env, not from argv.
*/
async function runFileService(): Promise<void> {
const root = process.env[USER_ROOT_ENV]
if (root === undefined || root === '') {
console.error(`file-service requires ${USER_ROOT_ENV} (the user's data root inside the Pod)`)
process.exit(2)
}
// The sidecar runs as the user's uid with no home dir; `homedir()` falls back
// to `/` and `resolveConfig` would try to mkdir `/.dshs`. It only
// needs `maxUploadBytes`/`logLevel` here, so pin dataRoot to a writable path
// and skip the (unused) encryption-secret file.
const config = resolveConfig({ dataRoot: '/tmp', encryptionSecret: 'file-service-unused' })
const app = buildFileService(root, { bodyLimit: config.maxUploadBytes, logLevel: config.logLevel })
await app.listen({ host: '0.0.0.0', port: FILE_SERVICE_PORT })
app.log.info(`file sidecar serving ${root} on 0.0.0.0:${FILE_SERVICE_PORT}`)
const shutdown = async (signal: string): Promise<void> => {
app.log.info(`received ${signal}, shutting down`)
await app.close()
@@ -188,22 +140,6 @@ async function runFileService(): Promise<void> {
process.on('SIGTERM', () => void shutdown('SIGTERM'))
}
/** TCP bridge sidecar (`dshs tcp-bridge <listen> <target>`). */
async function runTcpBridge(args: string[]): Promise<void> {
const [listen, target] = args
if (listen === undefined || target === undefined) {
console.error('usage: dshs tcp-bridge <listen> <target>')
process.exit(2)
}
const server = await startTcpBridge(listen, target)
console.error(`tcp-bridge ${listen} -> ${target}`)
const shutdown = (): void => {
server.close(() => process.exit(0))
}
process.on('SIGINT', shutdown)
process.on('SIGTERM', shutdown)
}
async function uidForUserCmd(args: string[]): Promise<void> {
const { values, positionals } = parseArgs({
args,
@@ -234,14 +170,6 @@ async function main(): Promise<void> {
await uidForUserCmd(rest)
return
}
if (first === 'file-service') {
await runFileService()
return
}
if (first === 'tcp-bridge') {
await runTcpBridge(rest)
return
}
await runServer(process.argv.slice(2))
}