Visitar URL original
feat: Add dualStack server option to the Feast operator by dbbvitor · Pull Request #6887 · feast-dev/feast · GitHub
Skip to content

feat: Add dualStack server option to the Feast operator - #6887

Open
dbbvitor wants to merge 15 commits into
feast-dev:masterfrom
dbbvitor:feat/operator-dual-stack
Open

dbbvitor wants to merge 15 commits into
feast-dev:masterfrom
dbbvitor:feat/operator-dual-stack

Conversation

@dbbvitor

Copy link
Copy Markdown
Contributor

What this PR does / why we need it:

Merge after #6886.

FeastServices renders every service container's command with a hardcoded IPv4 host flag (-h 0.0.0.0 for online/offline, or the ui/lineage servers' equivalent), with no CRD field to change it. On an IPv6-only or dual-stack cluster, none of these servers bind an address that anything can reach; the Operator half of the same gap #6886 already fixed on the SDK side.

This adds a DualStack *bool field to [ServerConfigs] https://github.com/dbbvitor/feast/blob/feat/operator-dual-stack/infra/feast-operator/api/v1/featurestore_types.go#L904). When set, a new withBindHost() helper rewrites the rendered -h argument pair to the IPv6 wildcard address instead of leaving the hardcoded IPv4 literal:

  • Online and offline servers (gunicorn, Arrow Flight) need the bracketed form ("[::]"), both reject a bare "::" as a host argument.
  • ui and lineage servers (uvicorn) reject the bracketed form and need the bare "::" instead.
  • The registry server takes no --host flag at all and is left untouched; it already always binds dual-stack.

withBindHost() is applied both inside getContainerCommand(), which builds each service Deployment's container args, and in setLineageDeployment(), which builds the lineage container's Command slice directly rather than going through the shared Args path.

Which issue(s) this PR fixes:

Part of #6862 (together with #6886 on the SDK side; don't let this auto-close the issue on merge; #6886 should merge first or alongside, since dualStack doesn't fully work for ui/lineage without it)

Checks

  • I've made sure the tests are passing.
  • My commits are signed off (git commit -s)
  • My PR title follows conventional commits format

Testing Strategy

  • Unit tests

Misc

  • DualStack is opt-in (nil/false preserves today's 0.0.0.0 behavior exactly), no change for clusters that don't set it.
  • This PR's -h :: for the ui/lineage (uvicorn-based) servers only works, end-to-end because fix: Bind metrics, REST registry, ui, and lineage servers dual-stack #6886 now also fixes ui_server.py's start_server() and lineage_server.py's start_lineage_server(): both previously called uvicorn.run(host=host, ...) directly, which sets IPV6_V6ONLY=1 via asyncio's loop.create_server() and would have made those two servers IPv6-only under this option, a silent IPv4 regression, not the dual-stack fix this PR promises.

Add a DualStack field to ServerConfigs that binds server processes to
the IPv6 wildcard address instead of 0.0.0.0, so they also accept IPv4
clients on dual-stack or IPv6-only clusters. Online and offline servers
use the bracketed [::] form required by gunicorn and Arrow Flight; ui,
lineage, and registry keep their existing behavior or use the bare ::
form uvicorn expects. The registry server always binds dual-stack and
ignores this setting.

Signed-off-by: dbbvitor <vitor.diniz@gympass.com>
Mutation testing found survivors in withBindHost's loop bounds: an -h
flag as the very last argument (no value to replace) and one as the
first argument were both untested edge cases.

Signed-off-by: dbbvitor <vitor.diniz@gympass.com>
@dbbvitor
dbbvitor requested a review from a team as a code owner September 29, 2026 00:21
@dbbvitor dbbvitor closed this Sep 29, 2026
@dbbvitor dbbvitor reopened this Sep 29, 2026
@codecov-commenter

codecov-commenter commented Sep 29, 2026 •

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 49.49%. Comparing base (87ef218) to head (cfab204).
⚠️ Report is 1 commits behind head on master.
❗ Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##           master    #6887   +/-   ##
=======================================
  Coverage   49.49%   49.49%           
=======================================
  Files         443      443           
  Lines       55451    55451           
  Branches     8085     8085           
=======================================
  Hits        27443    27443           
  Misses      26110    26110           
  Partials     1898     1898           
Flag Coverage Δ
go-feature-server 30.58% <ø> (ø)
python-unit 50.88% <ø> (ø)

Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update c005dc3...cfab204. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

dbbvitor and others added 7 commits September 29, 2026 23:03
The registry's REST server binds dual-stack by default in the SDK
CLI. Render -h 0.0.0.0 only when the shared DualStack field is
explicitly set to false, so nil/true keep today's dual-stack default
instead of silently going IPv4-only.

Signed-off-by: dbbvitor <vitor.diniz@gympass.com>
Only the generated_at metadata field diverged from master, which was
enough for GitHub to report this PR as unmergeable and apparently
skip queuing CI. No scan content changed.

Signed-off-by: dbbvitor <vitor.diniz@gympass.com>
@ntkathole

ntkathole commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

@dbbvitor I see asymmetry in default behavior, which is confusing:

  • For non-registry services: nil ≡ false → IPv4. User must opt-in with true.
  • For registry REST: nil ≡ true → dual-stack. User must opt-out with false.

I think it's better if one field, one meaning, everywhere.

dbbvitor and others added 2 commits October 5, 2026 16:22
Make unset or false dualStack render an explicit 0.0.0.0 host flag.
Only dualStack=true selects the bare IPv6 wildcard, aligning
registry REST defaults with other host-flag servers.

Signed-off-by: dbbvitor <vitor.diniz@gympass.com>
@dbbvitor
dbbvitor force-pushed the feat/operator-dual-stack branch from 40d8d19 to c2267df Compare October 5, 2026 19:52
@dbbvitor

dbbvitor commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

@dbbvitor I see asymmetry in default behavior, which is confusing:

  • For non-registry services: nil ≡ false → IPv4. User must opt-in with true.
  • For registry REST: nil ≡ true → dual-stack. User must opt-out with false.

I think it's better if one field, one meaning, everywhere.

Agreed. I've changed the code to remove the asymmetry in the design here: c2267df

@ntkathole

Copy link
Copy Markdown
Member

@dbbvitor can you please resolve the conflicts

…l-stack

Signed-off-by: dbbvitor <vitor.diniz@gympass.com>

# Conflicts:
#	.secrets.baseline
#	infra/feast-operator/internal/controller/services/services.go
@dbbvitor

dbbvitor commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

@ntkathole The ci error unit-test-go seems unrelated: {"level":"error","error":"open /home/runner/work/feast/feast/go/internal/test/feature_repo/data/registry.db: no such file or directory","time":"2026-10-07T20:09:40Z","message":"Registry Initialization Failed"}

Two consequences due to the recent change + upstream changes:

  • serve_registry only has -h from fix: Bind metrics, REST registry, ui, and lineage servers dual-stack #6886, so the registry REST server needs an image containing it (after 0.66.0), whether or not dualStack is set. Its old default was dual-stack, and it now needs dualStack: true for that.
  • The standalone mcpServer embeds ServerConfigs, so the CRD accepts dualStack there, but it has no effect. Binding MCP to IPv6 needs an SDK change too, so I'll send a follow-up PR right after this one.

@dbbvitor

dbbvitor commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Here is the related PR: #6977

dbbvitor and others added 2 commits October 8, 2026 10:15
Route the MCP --host through withBindHost, so mcpServer.dualStack renders :: instead of 0.0.0.0. The MCP server itself needs feast mcp --host :: support (feast-dev#6977).

Signed-off-by: dbbvitor <vitor.diniz@gympass.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants