add role deletion

This commit is contained in:
kkb0318
2024-05-26 16:30:17 +09:00
parent ddd3cff935
commit 2f1c707690
2 changed files with 17 additions and 6 deletions
+5 -5
View File
@@ -46,7 +46,7 @@ func (a *AwsIamClient) DeleteIRSARole(ctx context.Context, r RoleManager) error
}
_, err := a.Client.DetachRolePolicy(ctx, detachRolePolicyInput)
// Ignore error if the policy is already detached or the role does not exist
if errorHandle(err, []string{"NoSuchEntity"}) != nil {
if errorHandler(err, []string{"NoSuchEntity"}) != nil {
return err
}
log.Printf("Policy %s detached from role %s successfully", policy, r.RoleName)
@@ -55,7 +55,7 @@ func (a *AwsIamClient) DeleteIRSARole(ctx context.Context, r RoleManager) error
input := &iam.DeleteRoleInput{RoleName: aws.String(r.RoleName)}
_, err := a.Client.DeleteRole(ctx, input)
// Ignore error if the role does not exist or there are other policies that this controller does not manage
if errorHandle(err, []string{"DeleteConflict", "NoSuchEntity"}) != nil {
if errorHandler(err, []string{"DeleteConflict", "NoSuchEntity"}) != nil {
return err
}
log.Printf("Role %s deleted successfully", r.RoleName)
@@ -94,7 +94,7 @@ func (a *AwsIamClient) CreateIRSARole(ctx context.Context, issuerMeta issuer.OID
}
_, err = a.Client.CreateRole(context.TODO(), createRoleInput)
if errorHandle(err, []string{"EntityAlreadyExists"}) != nil {
if errorHandler(err, []string{"EntityAlreadyExists"}) != nil {
return err
}
log.Printf("Role %s created successfully", r.RoleName)
@@ -126,8 +126,8 @@ func (a *AwsIamClient) CreateIRSARole(ctx context.Context, issuerMeta issuer.OID
return nil
}
// errorHandle handles specific errors by checking the error code against a list of codes to ignore
func errorHandle(err error, errorCodes []string) error {
// errorHandler handles specific errors by checking the error code against a list of codes to ignore
func errorHandler(err error, errorCodes []string) error {
if err != nil {
var ae smithy.APIError
if errors.As(err, &ae) && slices.Contains(errorCodes, ae.ErrorCode()) {
+12 -1
View File
@@ -120,6 +120,17 @@ func (r *IRSAReconciler) reconcileDelete(ctx context.Context, obj *irsav1alpha1.
}
serviceAccount := obj.Spec.ServiceAccount
kubeHandler := handler.NewKubernetesHandler(kubeClient)
roleManager := awsclient.RoleManager{
RoleName: obj.Spec.IamRole.Name,
Policies: obj.Spec.IamPolicies,
}
err := r.AwsClient.IamClient().DeleteIRSARole(
ctx,
roleManager,
)
if err != nil {
return err
}
for _, ns := range serviceAccount.Namespaces {
sa := manifests.NewServiceAccountBuilder().Build(types.NamespacedName{
Name: serviceAccount.Name,
@@ -128,7 +139,7 @@ func (r *IRSAReconciler) reconcileDelete(ctx context.Context, obj *irsav1alpha1.
kubeHandler.Append(sa)
}
err := kubeHandler.DeleteAll(ctx)
err = kubeHandler.DeleteAll(ctx)
if err != nil {
return err
}