fix helm chart

This commit is contained in:
kkb0318
2024-06-02 15:15:59 +09:00
parent 979d08e695
commit 5eca211036
8 changed files with 458 additions and 433 deletions
+1 -1
View File
@@ -65,7 +65,7 @@ GOLANGCI_LINT_VERSION ?= v1.57.2
.PHONY: all .PHONY: all
all: fmt vet lint generate manifests kustomize helmify generate-docs all: fmt vet lint generate manifests kustomize helm generate-docs
##@ Development ##@ Development
+160
View File
@@ -0,0 +1,160 @@
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.14.0
name: irsas.irsa-manager.kkb0318.github.io
spec:
group: irsa-manager.kkb0318.github.io
names:
kind: IRSA
listKind: IRSAList
plural: irsas
singular: irsa
scope: Namespaced
versions:
- additionalPrinterColumns:
- jsonPath: .status.conditions[?(@.type=="Ready")].status
name: Ready
type: string
name: v1alpha1
schema:
openAPIV3Schema:
description: IRSA is the Schema for the irsas API
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
description: IRSASpec defines the desired state of IRSA
properties:
cleanup:
description: |-
Cleanup, when enabled, allows the IRSA to perform garbage collection
of resources that are no longer needed or managed.
type: boolean
iamPolicies:
description: |-
IamPolicies represents the list of IAM policies to be attached to the IAM role.
You can set both the policy name (only AWS default policies) or the full ARN.
items:
type: string
type: array
iamRole:
description: IamRole represents the IAM role details associated with
the IRSA.
properties:
name:
description: Name represents the name of the IAM role.
type: string
type: object
serviceAccount:
description: ServiceAccount represents the Kubernetes service account
associated with the IRSA.
properties:
name:
description: Name represents the name of the Kubernetes service
account
type: string
namespaces:
description: Namespaces represents the list of namespaces where
the service account is used
items:
type: string
type: array
type: object
required:
- cleanup
type: object
status:
description: IRSAStatus defines the observed state of IRSA.
properties:
conditions:
items:
description: "Condition contains details for one aspect of the current
state of this API Resource.\n---\nThis struct is intended for
direct use as an array at the field path .status.conditions. For
example,\n\n\n\ttype FooStatus struct{\n\t // Represents the
observations of a foo's current state.\n\t // Known .status.conditions.type
are: \"Available\", \"Progressing\", and \"Degraded\"\n\t //
+patchMergeKey=type\n\t // +patchStrategy=merge\n\t // +listType=map\n\t
\ // +listMapKey=type\n\t Conditions []metav1.Condition `json:\"conditions,omitempty\"
patchStrategy:\"merge\" patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t
\ // other fields\n\t}"
properties:
lastTransitionTime:
description: |-
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string
message:
description: |-
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength: 32768
type: string
observedGeneration:
description: |-
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format: int64
minimum: 0
type: integer
reason:
description: |-
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
type: string
status:
description: status of the condition, one of True, False, Unknown.
enum:
- "True"
- "False"
- Unknown
type: string
type:
description: |-
type of condition in CamelCase or in foo.example.com/CamelCase.
---
Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
useful (see .node.status.conditions), the ability to deconflict is important.
The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
type: array
type: object
type: object
served: true
storage: true
subresources:
status: {}
+86 -31
View File
@@ -13,11 +13,14 @@ spec:
singular: irsasetup singular: irsasetup
scope: Namespaced scope: Namespaced
versions: versions:
- name: v1alpha1 - additionalPrinterColumns:
- jsonPath: .status.selfHostedSetup[?(@.type=="Ready")].status
name: SelfHostedReady
type: string
name: v1alpha1
schema: schema:
openAPIV3Schema: openAPIV3Schema:
description: description: IRSASetup represents a configuration for setting up IAM Roles
IRSASetup represents a configuration for setting up IAM Roles
for Service Accounts (IRSA) in a Kubernetes cluster. for Service Accounts (IRSA) in a Kubernetes cluster.
properties: properties:
apiVersion: apiVersion:
@@ -40,44 +43,26 @@ spec:
spec: spec:
description: IRSASetupSpec defines the desired state of IRSASetup description: IRSASetupSpec defines the desired state of IRSASetup
properties: properties:
auth: cleanup:
description: Auth contains authentication configuration details. description: |-
properties: Cleanup, when enabled, allows the IRSASetup to perform garbage collection
secretRef: of resources that are no longer needed or managed.
description: type: boolean
SecretRef specifies the reference to the Kubernetes
secret containing authentication details.
properties:
name:
description: Name specifies the name of the secret.
type: string
namespace:
description: Namespace specifies the namespace of the secret.
type: string
required:
- name
type: object
required:
- secretRef
type: object
discovery: discovery:
description: |- description: |-
Discovery configures the IdP Discovery process, essential for setting up IRSA by locating Discovery configures the IdP Discovery process, essential for setting up IRSA by locating
the OIDC provider information. the OIDC provider information.
properties: properties:
s3: s3:
description: description: S3 specifies the AWS S3 bucket details where the
S3 specifies the AWS S3 bucket details where the
OIDC provider's discovery information is hosted. OIDC provider's discovery information is hosted.
properties: properties:
bucketName: bucketName:
description: description: BucketName is the name of the S3 bucket that
BucketName is the name of the S3 bucket that
hosts the OIDC discovery information. hosts the OIDC discovery information.
type: string type: string
region: region:
description: description: Region denotes the AWS region where the S3 bucket
Region denotes the AWS region where the S3 bucket
is located. is located.
type: string type: string
required: required:
@@ -86,16 +71,86 @@ spec:
type: object type: object
type: object type: object
mode: mode:
description: description: Mode specifies the mode of operation. Can be either "selfhosted"
Mode specifies the mode of operation. Can be either "selfhosted"
or "eks". or "eks".
type: string type: string
required: required:
- cleanup
- discovery - discovery
- mode - mode
type: object type: object
status: status:
description: IRSASetupStatus defines the observed state of IRSASetup description: IRSASetupStatus defines the observed state of IRSASetup
properties:
selfHostedSetup:
items:
description: "Condition contains details for one aspect of the current
state of this API Resource.\n---\nThis struct is intended for
direct use as an array at the field path .status.conditions. For
example,\n\n\n\ttype FooStatus struct{\n\t // Represents the
observations of a foo's current state.\n\t // Known .status.conditions.type
are: \"Available\", \"Progressing\", and \"Degraded\"\n\t //
+patchMergeKey=type\n\t // +patchStrategy=merge\n\t // +listType=map\n\t
\ // +listMapKey=type\n\t Conditions []metav1.Condition `json:\"conditions,omitempty\"
patchStrategy:\"merge\" patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t
\ // other fields\n\t}"
properties:
lastTransitionTime:
description: |-
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string
message:
description: |-
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength: 32768
type: string
observedGeneration:
description: |-
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format: int64
minimum: 0
type: integer
reason:
description: |-
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
type: string
status:
description: status of the condition, one of True, False, Unknown.
enum:
- "True"
- "False"
- Unknown
type: string
type:
description: |-
type of condition in CamelCase or in foo.example.com/CamelCase.
---
Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
useful (see .node.status.conditions), the ability to deconflict is important.
The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
type: array
type: object type: object
type: object type: object
served: true served: true
@@ -42,6 +42,26 @@ spec:
command: command:
- /manager - /manager
env: env:
- name: AWS_ACCESS_KEY_ID
valueFrom:
secretKeyRef:
key: aws-access-key-id
name: aws-secret
- name: AWS_SECRET_ACCESS_KEY
valueFrom:
secretKeyRef:
key: aws-secret-access-key
name: aws-secret
- name: AWS_REGION
valueFrom:
secretKeyRef:
key: aws-region
name: aws-secret
- name: AWS_ROLE_ARN
valueFrom:
secretKeyRef:
key: aws-role-arn
name: aws-secret
- name: KUBERNETES_CLUSTER_DOMAIN - name: KUBERNETES_CLUSTER_DOMAIN
value: {{ quote .Values.kubernetesClusterDomain }} value: {{ quote .Values.kubernetesClusterDomain }}
image: {{ .Values.controllerManager.manager.image.repository }}:{{ .Values.controllerManager.manager.image.tag image: {{ .Values.controllerManager.manager.image.repository }}:{{ .Values.controllerManager.manager.image.tag
@@ -5,6 +5,104 @@ metadata:
labels: labels:
{{- include "irsa-manager.labels" . | nindent 4 }} {{- include "irsa-manager.labels" . | nindent 4 }}
rules: rules:
- apiGroups:
- ""
resources:
- secrets
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
resources:
- serviceaccounts
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- ""
resources:
- services
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- admissionregistration.k8s.io
resources:
- mutatingwebhookconfigurations
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- apps
resources:
- deployments
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- certificates.k8s.io
resources:
- certificatesigningrequests
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- irsa-manager.kkb0318.github.io
resources:
- irsas
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- irsa-manager.kkb0318.github.io
resources:
- irsas/finalizers
verbs:
- update
- apiGroups:
- irsa-manager.kkb0318.github.io
resources:
- irsas/status
verbs:
- get
- patch
- update
- apiGroups: - apiGroups:
- irsa-manager.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
@@ -31,6 +129,30 @@ rules:
- get - get
- patch - patch
- update - update
- apiGroups:
- rbac.authorization.k8s.io
resources:
- clusterrolebindings
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- rbac.authorization.k8s.io
resources:
- clusterroles
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
--- ---
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding kind: ClusterRoleBinding
@@ -1,166 +0,0 @@
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.14.0
name: irsas.irsa-manager.kkb0318.github.io
spec:
group: irsa-manager.kkb0318.github.io
names:
kind: IRSA
listKind: IRSAList
plural: irsas
singular: irsa
scope: Namespaced
versions:
- additionalPrinterColumns:
- jsonPath: .status.conditions[?(@.type=="Ready")].status
name: Ready
type: string
name: v1alpha1
schema:
openAPIV3Schema:
description: IRSA is the Schema for the irsas API
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
description: IRSASpec defines the desired state of IRSA
properties:
cleanup:
description: |-
Cleanup, when enabled, allows the IRSA to perform garbage collection
of resources that are no longer needed or managed.
type: boolean
iamPolicies:
description: |-
IamPolicies represents the list of IAM policies to be attached to the IAM role.
You can set both the policy name (only AWS default policies) or the full ARN.
items:
type: string
type: array
iamRole:
description:
IamRole represents the IAM role details associated with
the IRSA.
properties:
name:
description: Name represents the name of the IAM role.
type: string
type: object
serviceAccount:
description:
ServiceAccount represents the Kubernetes service account
associated with the IRSA.
properties:
name:
description:
Name represents the name of the Kubernetes service
account
type: string
namespaces:
description:
Namespaces represents the list of namespaces where
the service account is used
items:
type: string
type: array
type: object
required:
- cleanup
type: object
status:
description: IRSAStatus defines the observed state of IRSA.
properties:
conditions:
items:
description:
"Condition contains details for one aspect of the current
state of this API Resource.\n---\nThis struct is intended for
direct use as an array at the field path .status.conditions. For
example,\n\n\n\ttype FooStatus struct{\n\t // Represents the
observations of a foo's current state.\n\t // Known .status.conditions.type
are: \"Available\", \"Progressing\", and \"Degraded\"\n\t //
+patchMergeKey=type\n\t // +patchStrategy=merge\n\t // +listType=map\n\t
\ // +listMapKey=type\n\t Conditions []metav1.Condition `json:\"conditions,omitempty\"
patchStrategy:\"merge\" patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t
\ // other fields\n\t}"
properties:
lastTransitionTime:
description: |-
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string
message:
description: |-
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength: 32768
type: string
observedGeneration:
description: |-
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format: int64
minimum: 0
type: integer
reason:
description: |-
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
type: string
status:
description: status of the condition, one of True, False, Unknown.
enum:
- "True"
- "False"
- Unknown
type: string
type:
description: |-
type of condition in CamelCase or in foo.example.com/CamelCase.
---
Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
useful (see .node.status.conditions), the ability to deconflict is important.
The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
type: array
type: object
type: object
served: true
storage: true
subresources:
status: {}
@@ -1,166 +0,0 @@
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.14.0
name: irsasetups.irsa-manager.kkb0318.github.io
spec:
group: irsa-manager.kkb0318.github.io
names:
kind: IRSASetup
listKind: IRSASetupList
plural: irsasetups
singular: irsasetup
scope: Namespaced
versions:
- additionalPrinterColumns:
- jsonPath: .status.selfHostedSetup[?(@.type=="Ready")].status
name: SelfHostedReady
type: string
name: v1alpha1
schema:
openAPIV3Schema:
description:
IRSASetup represents a configuration for setting up IAM Roles
for Service Accounts (IRSA) in a Kubernetes cluster.
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
description: IRSASetupSpec defines the desired state of IRSASetup
properties:
cleanup:
description: |-
Cleanup, when enabled, allows the IRSASetup to perform garbage collection
of resources that are no longer needed or managed.
type: boolean
discovery:
description: |-
Discovery configures the IdP Discovery process, essential for setting up IRSA by locating
the OIDC provider information.
properties:
s3:
description:
S3 specifies the AWS S3 bucket details where the
OIDC provider's discovery information is hosted.
properties:
bucketName:
description:
BucketName is the name of the S3 bucket that
hosts the OIDC discovery information.
type: string
region:
description:
Region denotes the AWS region where the S3 bucket
is located.
type: string
required:
- bucketName
- region
type: object
type: object
mode:
description:
Mode specifies the mode of operation. Can be either "selfhosted"
or "eks".
type: string
required:
- cleanup
- discovery
- mode
type: object
status:
description: IRSASetupStatus defines the observed state of IRSASetup
properties:
selfHostedSetup:
items:
description:
"Condition contains details for one aspect of the current
state of this API Resource.\n---\nThis struct is intended for
direct use as an array at the field path .status.conditions. For
example,\n\n\n\ttype FooStatus struct{\n\t // Represents the
observations of a foo's current state.\n\t // Known .status.conditions.type
are: \"Available\", \"Progressing\", and \"Degraded\"\n\t //
+patchMergeKey=type\n\t // +patchStrategy=merge\n\t // +listType=map\n\t
\ // +listMapKey=type\n\t Conditions []metav1.Condition `json:\"conditions,omitempty\"
patchStrategy:\"merge\" patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t
\ // other fields\n\t}"
properties:
lastTransitionTime:
description: |-
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string
message:
description: |-
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength: 32768
type: string
observedGeneration:
description: |-
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format: int64
minimum: 0
type: integer
reason:
description: |-
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
type: string
status:
description: status of the condition, one of True, False, Unknown.
enum:
- "True"
- "False"
- Unknown
type: string
type:
description: |-
type of condition in CamelCase or in foo.example.com/CamelCase.
---
Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
useful (see .node.status.conditions), the ability to deconflict is important.
The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
type: array
type: object
type: object
served: true
storage: true
subresources:
status: {}