From 2b73de798dd0095ca31cc1514608a7930f51918a Mon Sep 17 00:00:00 2001 From: kkb0318 Date: Sat, 1 Jun 2024 20:14:03 +0900 Subject: [PATCH] fix documents --- README.md | 29 +++++++++++-------- api/v1alpha1/irsa_types.go | 19 ++++++++---- .../bases/irsa.kkb0318.github.io_irsas.yaml | 13 +++++---- docs/api.md | 8 ++--- 4 files changed, 41 insertions(+), 28 deletions(-) diff --git a/README.md b/README.md index 129fd7e..f63e8db 100644 --- a/README.md +++ b/README.md @@ -64,16 +64,23 @@ spec: bucketName: ``` -4. Modify kube-apiserver Settings +4. Check the status -Execute the following commands on the control plane server to save the public and private keys for Kubernetes signatures: +Check the IRSASetup custom resource status to verify whether it is set to true. + +5. Modify kube-apiserver Settings + +If the IRSASetup status is true, a key file (Name: `irsa-manager-key` , Namespace: `kube-system` ) will be created. This is used for signing tokens in the kubernetes API. +Execute the following commands on the control plane server to save the public and private keys locally for Kubernetes signatures: ```console -kubectl get secret -n kube-system irsa-manager-key -o jsonpath="{.data.ssh-privatekey}" | base64 --decode | sudo tee /etc/kubernetes/pki/irsa-manager.key > /dev/null -kubectl get secret -n kube-system irsa-manager-key -o jsonpath="{.data.ssh-publickey}" | base64 --decode | sudo tee /etc/kubernetes/pki/irsa-manager.pub > /dev/null +kubectl get secret -n kube-system irsa-manager-key -o jsonpath="{.data.ssh-privatekey}" | base64 --decode | sudo tee /path/to/file.key > /dev/null +kubectl get secret -n kube-system irsa-manager-key -o jsonpath="{.data.ssh-publickey}" | base64 --decode | sudo tee /path/to/file.pub > /dev/null ``` -Then, modify the kube-apiserver.yaml file to include the following parameters: +> [!NOTE] > `/path/to/file` can be any path you choose. If you use kubeadm, it is recommended to set `/etc/kubernetes/pki/irsa-manager.(key|pub)` + +Then, modify the kube-apiserver settings to include the following parameters: - API Audiences @@ -89,32 +96,30 @@ Then, modify the kube-apiserver.yaml file to include the following parameters: - Service Account Key File -The public key (oidc-issuer.pub) generated previously can be read by the API server. Add the path for this parameter flag: +The public key generated previously can be read by the API server. Add the path for this parameter flag: ``` ---service-account-key-file=/etc/kubernetes/pki/irsa-manager.pub +--service-account-key-file=/path/to/file.pub ``` > [!NOTE] > Add this setting as the first element. If specified multiple times, tokens signed by any of the specified keys are considered valid by the Kubernetes API server. +> If you do not mount /path/to directory, you need to add the volumes field to this path. - Service Account Signing Key File The private key (oidc-issuer.key) generated previously can be read by the API server. Add the path for this parameter flag: ``` ---service-account-signing-key-file=/etc/kubernetes/pki/irsa-manager.key +--service-account-signing-key-file=/path/to/file.key ``` > [!NOTE] > Overwrite the existing settings. +> If you dont mount /path/to/file, you have to add the volumes field in this path For more details, refer to the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/#serviceaccount-token-volume-projection). -5. Check the status - -Check the IRSASetup custom resource status. If the status is true, you are ready to use IRSA. - ## How To Use You can set IRSA for the Kubernetes ServiceAccount. diff --git a/api/v1alpha1/irsa_types.go b/api/v1alpha1/irsa_types.go index ca59616..7f846c6 100644 --- a/api/v1alpha1/irsa_types.go +++ b/api/v1alpha1/irsa_types.go @@ -32,11 +32,18 @@ type IRSASpec struct { // of resources that are no longer needed or managed. // +required Cleanup bool `json:"cleanup"` - // ServiceAccount represents the Kubernetes service account associated with the IRSA + + // ServiceAccount represents the Kubernetes service account associated with the IRSA. + // +required ServiceAccount IRSAServiceAccount `json:"serviceAccount,omitempty"` - // IamRole represents the IAM role details associated with the IRSA + + // IamRole represents the IAM role details associated with the IRSA. + // +required IamRole IamRole `json:"iamRole,omitempty"` - // IamPolicies represents the list of IAM policies to be attached to the IAM role + + // IamPolicies represents the list of IAM policies to be attached to the IAM role. + // You can set both the policy name (only AWS default policies) or the full ARN. + // +required IamPolicies []string `json:"iamPolicies,omitempty"` } @@ -50,16 +57,16 @@ type IRSAServiceAccount struct { // IamRole represents the IAM role configuration type IamRole struct { - // Name represents the name of the IAM role + // Name represents the name of the IAM role. Name string `json:"name,omitempty"` } -// IRSAStatus defines the observed state of IRSA +// IRSAStatus defines the observed state of IRSA. type IRSAStatus struct { Conditions []metav1.Condition `json:"conditions,omitempty"` } -// GetIRSAStatusConditions returns a pointer to the Status.Conditions slice +// GetIRSAStatusConditions returns a pointer to the Conditions slice func (in *IRSA) GetIRSAStatusConditions() *[]metav1.Condition { return &in.Status.Conditions } diff --git a/config/crd/bases/irsa.kkb0318.github.io_irsas.yaml b/config/crd/bases/irsa.kkb0318.github.io_irsas.yaml index 0e059c1..a5fca35 100644 --- a/config/crd/bases/irsa.kkb0318.github.io_irsas.yaml +++ b/config/crd/bases/irsa.kkb0318.github.io_irsas.yaml @@ -49,22 +49,23 @@ spec: of resources that are no longer needed or managed. type: boolean iamPolicies: - description: IamPolicies represents the list of IAM policies to be - attached to the IAM role + description: |- + IamPolicies represents the list of IAM policies to be attached to the IAM role. + You can set both the policy name (only AWS default policies) or the full ARN. items: type: string type: array iamRole: description: IamRole represents the IAM role details associated with - the IRSA + the IRSA. properties: name: - description: Name represents the name of the IAM role + description: Name represents the name of the IAM role. type: string type: object serviceAccount: description: ServiceAccount represents the Kubernetes service account - associated with the IRSA + associated with the IRSA. properties: name: description: Name represents the name of the Kubernetes service @@ -81,7 +82,7 @@ spec: - cleanup type: object status: - description: IRSAStatus defines the observed state of IRSA + description: IRSAStatus defines the observed state of IRSA. properties: conditions: items: diff --git a/docs/api.md b/docs/api.md index 43937af..89eebd7 100644 --- a/docs/api.md +++ b/docs/api.md @@ -137,9 +137,9 @@ _Appears in:_ | Field | Description | Default | Validation | | --- | --- | --- | --- | | `cleanup` _boolean_ | Cleanup, when enabled, allows the IRSA to perform garbage collection
of resources that are no longer needed or managed. | | | -| `serviceAccount` _[IRSAServiceAccount](#irsaserviceaccount)_ | ServiceAccount represents the Kubernetes service account associated with the IRSA | | | -| `iamRole` _[IamRole](#iamrole)_ | IamRole represents the IAM role details associated with the IRSA | | | -| `iamPolicies` _string array_ | IamPolicies represents the list of IAM policies to be attached to the IAM role | | | +| `serviceAccount` _[IRSAServiceAccount](#irsaserviceaccount)_ | ServiceAccount represents the Kubernetes service account associated with the IRSA. | | | +| `iamRole` _[IamRole](#iamrole)_ | IamRole represents the IAM role details associated with the IRSA. | | | +| `iamPolicies` _string array_ | IamPolicies represents the list of IAM policies to be attached to the IAM role.
You can set both the policy name (only AWS default policies) or the full ARN. | | | @@ -157,7 +157,7 @@ _Appears in:_ | Field | Description | Default | Validation | | --- | --- | --- | --- | -| `name` _string_ | Name represents the name of the IAM role | | | +| `name` _string_ | Name represents the name of the IAM role. | | | #### S3Discovery