v0.74.0: fix controller->agent connection leak (reuse one agentapi client)
agentClient() built a new agentapi.Client (new bare http.Transport, IdleConnTimeout:0) per call and discarded it without closing idle conns -> one leaked idle ESTABLISHED socket per call to the agent :8443, exhausting the ephemeral port range after ~5 days (EADDRNOTAVAIL). Memoize one shared client via sync.Once; harden Transport (MaxIdleConns/PerHost + IdleConnTimeout 90s). Agent/firewall untouched. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -84,12 +84,26 @@ func New(endpoint, token, fingerprintHex string) (*Client, error) {
|
||||
baseURL: "https://" + endpoint,
|
||||
token: token,
|
||||
hc: &http.Client{
|
||||
Timeout: 15 * time.Second,
|
||||
Transport: &http.Transport{TLSClientConfig: tlsCfg},
|
||||
Timeout: 15 * time.Second,
|
||||
// Bound + expire the idle-conn pool. With the controller reusing one Client (so the pool
|
||||
// stays ~2), IdleConnTimeout also lets idle conns to a RESTARTED agent drain instead of
|
||||
// lingering as stale ESTABLISHED entries, and caps any future per-call misuse. (The earlier
|
||||
// bare Transport had IdleConnTimeout:0 = idle keep-alives never expire → the leak.)
|
||||
Transport: &http.Transport{
|
||||
TLSClientConfig: tlsCfg,
|
||||
MaxIdleConns: 4,
|
||||
MaxIdleConnsPerHost: 2,
|
||||
IdleConnTimeout: 90 * time.Second,
|
||||
},
|
||||
},
|
||||
}, nil
|
||||
}
|
||||
|
||||
// Close releases the client's idle keep-alive connections. Optional hygiene for any caller that builds
|
||||
// a short-lived client; the controller reuses one long-lived client, so it relies on the bounded,
|
||||
// expiring idle pool (above) rather than calling this.
|
||||
func (c *Client) Close() { c.hc.CloseIdleConnections() }
|
||||
|
||||
// Storage calls GET /storage and returns this guest's mounts (connectivity + placement view).
|
||||
func (c *Client) Storage(ctx context.Context) (StorageResponse, error) {
|
||||
var out StorageResponse
|
||||
|
||||
Reference in New Issue
Block a user