fix api definition (optional mode)

This commit is contained in:
kkb0318
2024-06-16 14:43:41 +09:00
parent 074738f29c
commit 25ae093bc4
9 changed files with 34 additions and 23 deletions
+5 -2
View File
@@ -33,8 +33,11 @@ type IRSASetupSpec struct {
// +required // +required
Cleanup bool `json:"cleanup"` Cleanup bool `json:"cleanup"`
// Mode specifies the mode of operation. Can be either "selfhosted" or "eks". // Mode (Optional, Future Feature) Defines how the controller will operate once this feature is enabled.
Mode string `json:"mode"` // Currently unused. Planned values:
// - "selfhosted": For self-managed Kubernetes clusters.
// - "eks": For Amazon EKS environments.
Mode string `json:"mode,omitempty"`
// Discovery configures the IdP Discovery process, essential for setting up IRSA by locating // Discovery configures the IdP Discovery process, essential for setting up IRSA by locating
// the OIDC provider information. // the OIDC provider information.
+5 -3
View File
@@ -71,13 +71,15 @@ spec:
type: object type: object
type: object type: object
mode: mode:
description: Mode specifies the mode of operation. Can be either "selfhosted" description: |-
or "eks". Mode (Optional, Future Feature) Defines how the controller will operate once this feature is enabled.
Currently unused. Planned values:
- "selfhosted": For self-managed Kubernetes clusters.
- "eks": For Amazon EKS environments.
type: string type: string
required: required:
- cleanup - cleanup
- discovery - discovery
- mode
type: object type: object
status: status:
description: IRSASetupStatus defines the observed state of IRSASetup description: IRSASetupStatus defines the observed state of IRSASetup
@@ -62,6 +62,7 @@ spec:
secretKeyRef: secretKeyRef:
key: aws-role-arn key: aws-role-arn
name: aws-secret name: aws-secret
optional: true
- name: KUBERNETES_CLUSTER_DOMAIN - name: KUBERNETES_CLUSTER_DOMAIN
value: {{ quote .Values.kubernetesClusterDomain }} value: {{ quote .Values.kubernetesClusterDomain }}
image: {{ .Values.controllerManager.manager.image.repository }}:{{ .Values.controllerManager.manager.image.tag image: {{ .Values.controllerManager.manager.image.repository }}:{{ .Values.controllerManager.manager.image.tag
@@ -72,13 +72,15 @@ spec:
type: object type: object
type: object type: object
mode: mode:
description: Mode specifies the mode of operation. Can be either "selfhosted" description: |-
or "eks". Mode (Optional, Future Feature) Defines how the controller will operate once this feature is enabled.
Currently unused. Planned values:
- "selfhosted": For self-managed Kubernetes clusters.
- "eks": For Amazon EKS environments.
type: string type: string
required: required:
- cleanup - cleanup
- discovery - discovery
- mode
type: object type: object
status: status:
description: IRSASetupStatus defines the observed state of IRSASetup description: IRSASetupStatus defines the observed state of IRSASetup
+1 -1
View File
@@ -95,7 +95,7 @@ spec:
secretKeyRef: secretKeyRef:
name: aws-secret name: aws-secret
key: aws-role-arn key: aws-role-arn
# optional: true optional: true
name: manager name: manager
securityContext: securityContext:
allowPrivilegeEscalation: false allowPrivilegeEscalation: false
+1 -1
View File
@@ -100,7 +100,7 @@ _Appears in:_
| Field | Description | Default | Validation | | Field | Description | Default | Validation |
| --- | --- | --- | --- | | --- | --- | --- | --- |
| `cleanup` _boolean_ | Cleanup, when enabled, allows the IRSASetup to perform garbage collection<br />of resources that are no longer needed or managed. | | | | `cleanup` _boolean_ | Cleanup, when enabled, allows the IRSASetup to perform garbage collection<br />of resources that are no longer needed or managed. | | |
| `mode` _string_ | Mode specifies the mode of operation. Can be either "selfhosted" or "eks". | | | | `mode` _string_ | Mode (Optional, Future Feature) Defines how the controller will operate once this feature is enabled.<br />Currently unused. Planned values:<br /> - "selfhosted": For self-managed Kubernetes clusters.<br /> - "eks": For Amazon EKS environments. | | |
| `discovery` _[Discovery](#discovery)_ | Discovery configures the IdP Discovery process, essential for setting up IRSA by locating<br />the OIDC provider information. | | | | `discovery` _[Discovery](#discovery)_ | Discovery configures the IdP Discovery process, essential for setting up IRSA by locating<br />the OIDC provider information. | | |
-1
View File
@@ -5,7 +5,6 @@ metadata:
namespace: irsa-manager-system namespace: irsa-manager-system
spec: spec:
cleanup: false cleanup: false
mode: selfhosted
discovery: discovery:
s3: s3:
region: ap-northeast-1 region: ap-northeast-1
@@ -53,7 +53,7 @@ var _ = Describe("IRSASetup Controller", func() {
}, },
Spec: irsav1alpha1.IRSASetupSpec{ Spec: irsav1alpha1.IRSASetupSpec{
Cleanup: true, Cleanup: true,
Mode: "selfhosted", // Mode: "selfhosted",
Discovery: irsav1alpha1.Discovery{ Discovery: irsav1alpha1.Discovery{
S3: irsav1alpha1.S3Discovery{ S3: irsav1alpha1.S3Discovery{
Region: "ap-northeast-1", Region: "ap-northeast-1",
@@ -134,7 +134,7 @@ var _ = Describe("IRSASetup Controller", func() {
}, },
Spec: irsav1alpha1.IRSASetupSpec{ Spec: irsav1alpha1.IRSASetupSpec{
Cleanup: true, Cleanup: true,
Mode: "selfhoted", // Mode: "selfhoted",
Discovery: irsav1alpha1.Discovery{ Discovery: irsav1alpha1.Discovery{
S3: irsav1alpha1.S3Discovery{ S3: irsav1alpha1.S3Discovery{
Region: "ap-northeast-1", Region: "ap-northeast-1",
@@ -219,7 +219,7 @@ var _ = Describe("IRSASetup Controller", func() {
}, },
Spec: irsav1alpha1.IRSASetupSpec{ Spec: irsav1alpha1.IRSASetupSpec{
Cleanup: false, Cleanup: false,
Mode: "selfhoted", // Mode: "selfhoted",
Discovery: irsav1alpha1.Discovery{ Discovery: irsav1alpha1.Discovery{
S3: irsav1alpha1.S3Discovery{ S3: irsav1alpha1.S3Discovery{
Region: "ap-northeast-1", Region: "ap-northeast-1",
@@ -19,21 +19,25 @@ func TestCreateTlsCredentials(t *testing.T) {
} }
certBlock, _ := pem.Decode(creds.certificate) certBlock, _ := pem.Decode(creds.certificate)
var cert *x509.Certificate
if certBlock == nil { if certBlock == nil {
t.Fatal("Failed to decode PEM block containing the certificate") t.Fatal("Failed to decode PEM block containing the certificate")
} else {
cert, err = x509.ParseCertificate(certBlock.Bytes)
if err != nil {
t.Fatalf("Failed to parse certificate: %v", err)
}
} }
cert, err := x509.ParseCertificate(certBlock.Bytes) var key *rsa.PrivateKey
if err != nil {
t.Fatalf("Failed to parse certificate: %v", err)
}
keyBlock, _ := pem.Decode(creds.privateKey) keyBlock, _ := pem.Decode(creds.privateKey)
if keyBlock == nil { if keyBlock == nil {
t.Fatal("Failed to decode PEM block containing the private key") t.Fatal("Failed to decode PEM block containing the private key")
} } else {
key, err := x509.ParsePKCS1PrivateKey(keyBlock.Bytes) key, err = x509.ParsePKCS1PrivateKey(keyBlock.Bytes)
if err != nil { if err != nil {
t.Fatalf("Failed to parse private key: %v", err) t.Fatalf("Failed to parse private key: %v", err)
}
} }
// Verify public keys are equivalent // Verify public keys are equivalent