fix api definition (optional mode)

This commit is contained in:
kkb0318
2024-06-16 14:43:41 +09:00
parent 074738f29c
commit 25ae093bc4
9 changed files with 34 additions and 23 deletions
+5 -2
View File
@@ -33,8 +33,11 @@ type IRSASetupSpec struct {
// +required
Cleanup bool `json:"cleanup"`
// Mode specifies the mode of operation. Can be either "selfhosted" or "eks".
Mode string `json:"mode"`
// Mode (Optional, Future Feature) Defines how the controller will operate once this feature is enabled.
// Currently unused. Planned values:
// - "selfhosted": For self-managed Kubernetes clusters.
// - "eks": For Amazon EKS environments.
Mode string `json:"mode,omitempty"`
// Discovery configures the IdP Discovery process, essential for setting up IRSA by locating
// the OIDC provider information.
+5 -3
View File
@@ -71,13 +71,15 @@ spec:
type: object
type: object
mode:
description: Mode specifies the mode of operation. Can be either "selfhosted"
or "eks".
description: |-
Mode (Optional, Future Feature) Defines how the controller will operate once this feature is enabled.
Currently unused. Planned values:
- "selfhosted": For self-managed Kubernetes clusters.
- "eks": For Amazon EKS environments.
type: string
required:
- cleanup
- discovery
- mode
type: object
status:
description: IRSASetupStatus defines the observed state of IRSASetup
@@ -62,6 +62,7 @@ spec:
secretKeyRef:
key: aws-role-arn
name: aws-secret
optional: true
- name: KUBERNETES_CLUSTER_DOMAIN
value: {{ quote .Values.kubernetesClusterDomain }}
image: {{ .Values.controllerManager.manager.image.repository }}:{{ .Values.controllerManager.manager.image.tag
@@ -72,13 +72,15 @@ spec:
type: object
type: object
mode:
description: Mode specifies the mode of operation. Can be either "selfhosted"
or "eks".
description: |-
Mode (Optional, Future Feature) Defines how the controller will operate once this feature is enabled.
Currently unused. Planned values:
- "selfhosted": For self-managed Kubernetes clusters.
- "eks": For Amazon EKS environments.
type: string
required:
- cleanup
- discovery
- mode
type: object
status:
description: IRSASetupStatus defines the observed state of IRSASetup
+1 -1
View File
@@ -95,7 +95,7 @@ spec:
secretKeyRef:
name: aws-secret
key: aws-role-arn
# optional: true
optional: true
name: manager
securityContext:
allowPrivilegeEscalation: false
+1 -1
View File
@@ -100,7 +100,7 @@ _Appears in:_
| Field | Description | Default | Validation |
| --- | --- | --- | --- |
| `cleanup` _boolean_ | Cleanup, when enabled, allows the IRSASetup to perform garbage collection<br />of resources that are no longer needed or managed. | | |
| `mode` _string_ | Mode specifies the mode of operation. Can be either "selfhosted" or "eks". | | |
| `mode` _string_ | Mode (Optional, Future Feature) Defines how the controller will operate once this feature is enabled.<br />Currently unused. Planned values:<br /> - "selfhosted": For self-managed Kubernetes clusters.<br /> - "eks": For Amazon EKS environments. | | |
| `discovery` _[Discovery](#discovery)_ | Discovery configures the IdP Discovery process, essential for setting up IRSA by locating<br />the OIDC provider information. | | |
-1
View File
@@ -5,7 +5,6 @@ metadata:
namespace: irsa-manager-system
spec:
cleanup: false
mode: selfhosted
discovery:
s3:
region: ap-northeast-1
@@ -53,7 +53,7 @@ var _ = Describe("IRSASetup Controller", func() {
},
Spec: irsav1alpha1.IRSASetupSpec{
Cleanup: true,
Mode: "selfhosted",
// Mode: "selfhosted",
Discovery: irsav1alpha1.Discovery{
S3: irsav1alpha1.S3Discovery{
Region: "ap-northeast-1",
@@ -134,7 +134,7 @@ var _ = Describe("IRSASetup Controller", func() {
},
Spec: irsav1alpha1.IRSASetupSpec{
Cleanup: true,
Mode: "selfhoted",
// Mode: "selfhoted",
Discovery: irsav1alpha1.Discovery{
S3: irsav1alpha1.S3Discovery{
Region: "ap-northeast-1",
@@ -219,7 +219,7 @@ var _ = Describe("IRSASetup Controller", func() {
},
Spec: irsav1alpha1.IRSASetupSpec{
Cleanup: false,
Mode: "selfhoted",
// Mode: "selfhoted",
Discovery: irsav1alpha1.Discovery{
S3: irsav1alpha1.S3Discovery{
Region: "ap-northeast-1",
@@ -19,23 +19,27 @@ func TestCreateTlsCredentials(t *testing.T) {
}
certBlock, _ := pem.Decode(creds.certificate)
var cert *x509.Certificate
if certBlock == nil {
t.Fatal("Failed to decode PEM block containing the certificate")
}
cert, err := x509.ParseCertificate(certBlock.Bytes)
} else {
cert, err = x509.ParseCertificate(certBlock.Bytes)
if err != nil {
t.Fatalf("Failed to parse certificate: %v", err)
}
}
var key *rsa.PrivateKey
keyBlock, _ := pem.Decode(creds.privateKey)
if keyBlock == nil {
t.Fatal("Failed to decode PEM block containing the private key")
}
key, err := x509.ParsePKCS1PrivateKey(keyBlock.Bytes)
} else {
key, err = x509.ParsePKCS1PrivateKey(keyBlock.Bytes)
if err != nil {
t.Fatalf("Failed to parse private key: %v", err)
}
}
// Verify public keys are equivalent
if !publicKeysEqual(cert.PublicKey, &key.PublicKey) {
t.Fatal("Public key in certificate does not match public key in private key")