From 2f1c70769081b2e37d1458fbf3a9ae0773706563 Mon Sep 17 00:00:00 2001 From: kkb0318 Date: Sun, 26 May 2024 16:30:17 +0900 Subject: [PATCH] add role deletion --- internal/aws/aws_role.go | 10 +++++----- internal/controller/irsa_controller.go | 13 ++++++++++++- 2 files changed, 17 insertions(+), 6 deletions(-) diff --git a/internal/aws/aws_role.go b/internal/aws/aws_role.go index 24c602c..fd472c7 100644 --- a/internal/aws/aws_role.go +++ b/internal/aws/aws_role.go @@ -46,7 +46,7 @@ func (a *AwsIamClient) DeleteIRSARole(ctx context.Context, r RoleManager) error } _, err := a.Client.DetachRolePolicy(ctx, detachRolePolicyInput) // Ignore error if the policy is already detached or the role does not exist - if errorHandle(err, []string{"NoSuchEntity"}) != nil { + if errorHandler(err, []string{"NoSuchEntity"}) != nil { return err } log.Printf("Policy %s detached from role %s successfully", policy, r.RoleName) @@ -55,7 +55,7 @@ func (a *AwsIamClient) DeleteIRSARole(ctx context.Context, r RoleManager) error input := &iam.DeleteRoleInput{RoleName: aws.String(r.RoleName)} _, err := a.Client.DeleteRole(ctx, input) // Ignore error if the role does not exist or there are other policies that this controller does not manage - if errorHandle(err, []string{"DeleteConflict", "NoSuchEntity"}) != nil { + if errorHandler(err, []string{"DeleteConflict", "NoSuchEntity"}) != nil { return err } log.Printf("Role %s deleted successfully", r.RoleName) @@ -94,7 +94,7 @@ func (a *AwsIamClient) CreateIRSARole(ctx context.Context, issuerMeta issuer.OID } _, err = a.Client.CreateRole(context.TODO(), createRoleInput) - if errorHandle(err, []string{"EntityAlreadyExists"}) != nil { + if errorHandler(err, []string{"EntityAlreadyExists"}) != nil { return err } log.Printf("Role %s created successfully", r.RoleName) @@ -126,8 +126,8 @@ func (a *AwsIamClient) CreateIRSARole(ctx context.Context, issuerMeta issuer.OID return nil } -// errorHandle handles specific errors by checking the error code against a list of codes to ignore -func errorHandle(err error, errorCodes []string) error { +// errorHandler handles specific errors by checking the error code against a list of codes to ignore +func errorHandler(err error, errorCodes []string) error { if err != nil { var ae smithy.APIError if errors.As(err, &ae) && slices.Contains(errorCodes, ae.ErrorCode()) { diff --git a/internal/controller/irsa_controller.go b/internal/controller/irsa_controller.go index 21ce8a5..0c8590b 100644 --- a/internal/controller/irsa_controller.go +++ b/internal/controller/irsa_controller.go @@ -120,6 +120,17 @@ func (r *IRSAReconciler) reconcileDelete(ctx context.Context, obj *irsav1alpha1. } serviceAccount := obj.Spec.ServiceAccount kubeHandler := handler.NewKubernetesHandler(kubeClient) + roleManager := awsclient.RoleManager{ + RoleName: obj.Spec.IamRole.Name, + Policies: obj.Spec.IamPolicies, + } + err := r.AwsClient.IamClient().DeleteIRSARole( + ctx, + roleManager, + ) + if err != nil { + return err + } for _, ns := range serviceAccount.Namespaces { sa := manifests.NewServiceAccountBuilder().Build(types.NamespacedName{ Name: serviceAccount.Name, @@ -128,7 +139,7 @@ func (r *IRSAReconciler) reconcileDelete(ctx context.Context, obj *irsav1alpha1. kubeHandler.Append(sa) } - err := kubeHandler.DeleteAll(ctx) + err = kubeHandler.DeleteAll(ctx) if err != nil { return err }