diff --git a/api/v1alpha1/irsasetup_types.go b/api/v1alpha1/irsasetup_types.go index f864274..5385636 100644 --- a/api/v1alpha1/irsasetup_types.go +++ b/api/v1alpha1/irsasetup_types.go @@ -20,16 +20,53 @@ import ( metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" ) -// EDIT THIS FILE! THIS IS SCAFFOLDING FOR YOU TO OWN! -// NOTE: json tags are required. Any new fields you add must have json tags for the fields to be serialized. +const ( + // IRSASetupKind represents the kind attribute of an IRSASetup resource. + IRSASetupKind = "IRSASetup" +) // IRSASetupSpec defines the desired state of IRSASetup type IRSASetupSpec struct { - // INSERT ADDITIONAL SPEC FIELDS - desired state of cluster - // Important: Run "make" to regenerate code after modifying this file + // Mode specifies the mode of operation. Can be either "selfhosted" or "eks". + Mode string `json:"mode"` - // Foo is an example field of IRSASetup. Edit irsasetup_types.go to remove/update - Foo string `json:"foo,omitempty"` + // Discovery configures the IdP Discovery process, essential for setting up IRSA by locating + // the OIDC provider information. + Discovery Discovery `json:"discovery"` + + // Auth contains authentication configuration details. + Auth Auth `json:"auth,omitempty"` +} + +// Discovery holds the configuration for IdP Discovery, which is crucial for locating +// the OIDC provider in a self-hosted environment. +type Discovery struct { + // S3 specifies the AWS S3 bucket details where the OIDC provider's discovery information is hosted. + S3 S3Discovery `json:"s3,omitempty"` +} + +// S3Discovery contains the specifics of the S3 bucket used for hosting OIDC provider discovery information. +type S3Discovery struct { + // Region denotes the AWS region where the S3 bucket is located. + Region string `json:"region"` + + // BucketName is the name of the S3 bucket that hosts the OIDC discovery information. + BucketName string `json:"bucketName"` +} + +// Auth holds the authentication configuration details. +type Auth struct { + // SecretRef specifies the reference to the Kubernetes secret containing authentication details. + SecretRef SecretRef `json:"secretRef"` +} + +// SecretRef contains the reference to a Kubernetes secret. +type SecretRef struct { + // Name specifies the name of the secret. + Name string `json:"name"` + + // Namespace specifies the namespace of the secret. + Namespace string `json:"namespace,omitempty"` } // IRSASetupStatus defines the observed state of IRSASetup @@ -41,7 +78,7 @@ type IRSASetupStatus struct { //+kubebuilder:object:root=true //+kubebuilder:subresource:status -// IRSASetup is the Schema for the irsasetups API +// IRSASetup represents a configuration for setting up IAM Roles for Service Accounts (IRSA) in a Kubernetes cluster. type IRSASetup struct { metav1.TypeMeta `json:",inline"` metav1.ObjectMeta `json:"metadata,omitempty"` diff --git a/api/v1alpha1/zz_generated.deepcopy.go b/api/v1alpha1/zz_generated.deepcopy.go index 75e888d..096bd18 100644 --- a/api/v1alpha1/zz_generated.deepcopy.go +++ b/api/v1alpha1/zz_generated.deepcopy.go @@ -24,6 +24,38 @@ import ( runtime "k8s.io/apimachinery/pkg/runtime" ) +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *Auth) DeepCopyInto(out *Auth) { + *out = *in + out.SecretRef = in.SecretRef +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Auth. +func (in *Auth) DeepCopy() *Auth { + if in == nil { + return nil + } + out := new(Auth) + in.DeepCopyInto(out) + return out +} + +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *Discovery) DeepCopyInto(out *Discovery) { + *out = *in + out.S3 = in.S3 +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Discovery. +func (in *Discovery) DeepCopy() *Discovery { + if in == nil { + return nil + } + out := new(Discovery) + in.DeepCopyInto(out) + return out +} + // DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. func (in *IRSASetup) DeepCopyInto(out *IRSASetup) { *out = *in @@ -86,6 +118,8 @@ func (in *IRSASetupList) DeepCopyObject() runtime.Object { // DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. func (in *IRSASetupSpec) DeepCopyInto(out *IRSASetupSpec) { *out = *in + out.Discovery = in.Discovery + out.Auth = in.Auth } // DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new IRSASetupSpec. @@ -112,3 +146,33 @@ func (in *IRSASetupStatus) DeepCopy() *IRSASetupStatus { in.DeepCopyInto(out) return out } + +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *S3Discovery) DeepCopyInto(out *S3Discovery) { + *out = *in +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new S3Discovery. +func (in *S3Discovery) DeepCopy() *S3Discovery { + if in == nil { + return nil + } + out := new(S3Discovery) + in.DeepCopyInto(out) + return out +} + +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *SecretRef) DeepCopyInto(out *SecretRef) { + *out = *in +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SecretRef. +func (in *SecretRef) DeepCopy() *SecretRef { + if in == nil { + return nil + } + out := new(SecretRef) + in.DeepCopyInto(out) + return out +} diff --git a/config/crd/bases/irsa.kkb0318.github.io_irsasetups.yaml b/config/crd/bases/irsa.kkb0318.github.io_irsasetups.yaml index 8b63078..1b5cd92 100644 --- a/config/crd/bases/irsa.kkb0318.github.io_irsasetups.yaml +++ b/config/crd/bases/irsa.kkb0318.github.io_irsasetups.yaml @@ -17,7 +17,8 @@ spec: - name: v1alpha1 schema: openAPIV3Schema: - description: IRSASetup is the Schema for the irsasetups API + description: IRSASetup represents a configuration for setting up IAM Roles + for Service Accounts (IRSA) in a Kubernetes cluster. properties: apiVersion: description: |- @@ -39,10 +40,54 @@ spec: spec: description: IRSASetupSpec defines the desired state of IRSASetup properties: - foo: - description: Foo is an example field of IRSASetup. Edit irsasetup_types.go - to remove/update + auth: + description: Auth contains authentication configuration details. + properties: + secretRef: + description: SecretRef specifies the reference to the Kubernetes + secret containing authentication details. + properties: + name: + description: Name specifies the name of the secret. + type: string + namespace: + description: Namespace specifies the namespace of the secret. + type: string + required: + - name + type: object + required: + - secretRef + type: object + discovery: + description: |- + Discovery configures the IdP Discovery process, essential for setting up IRSA by locating + the OIDC provider information. + properties: + s3: + description: S3 specifies the AWS S3 bucket details where the + OIDC provider's discovery information is hosted. + properties: + bucketName: + description: BucketName is the name of the S3 bucket that + hosts the OIDC discovery information. + type: string + region: + description: Region denotes the AWS region where the S3 bucket + is located. + type: string + required: + - bucketName + - region + type: object + type: object + mode: + description: Mode specifies the mode of operation. Can be either "selfhosted" + or "eks". type: string + required: + - discovery + - mode type: object status: description: IRSASetupStatus defines the observed state of IRSASetup