From 6016727837bf38dbc7b0a380f7b8af3fdb695cb7 Mon Sep 17 00:00:00 2001 From: kkb0318 Date: Sat, 1 Jun 2024 20:56:58 +0900 Subject: [PATCH] modify unused apis, fix docs --- README.md | 5 ++- api/v1alpha1/irsasetup_types.go | 18 ---------- api/v1alpha1/zz_generated.deepcopy.go | 32 ----------------- .../irsa.kkb0318.github.io_irsasetups.yaml | 19 ----------- docs/api.md | 34 ------------------- 5 files changed, 4 insertions(+), 104 deletions(-) diff --git a/README.md b/README.md index 48f5659..6c0d272 100644 --- a/README.md +++ b/README.md @@ -67,7 +67,10 @@ spec: Check the IRSASetup custom resource status to verify whether it is set to true. -5. Modify kube-apiserver Settings +> [!NOTE] +> Please ensure that only one IRSASetup resource is created. + +4. Modify kube-apiserver Settings If the IRSASetup status is true, a key file (Name: `irsa-manager-key` , Namespace: `kube-system` ) will be created. This is used for signing tokens in the kubernetes API. Execute the following commands on the control plane server to save the public and private keys locally for Kubernetes signatures: diff --git a/api/v1alpha1/irsasetup_types.go b/api/v1alpha1/irsasetup_types.go index d5a0677..30f7b7c 100644 --- a/api/v1alpha1/irsasetup_types.go +++ b/api/v1alpha1/irsasetup_types.go @@ -39,9 +39,6 @@ type IRSASetupSpec struct { // Discovery configures the IdP Discovery process, essential for setting up IRSA by locating // the OIDC provider information. Discovery Discovery `json:"discovery"` - - // Auth contains authentication configuration details. - Auth Auth `json:"auth,omitempty"` } // Discovery holds the configuration for IdP Discovery, which is crucial for locating @@ -60,21 +57,6 @@ type S3Discovery struct { BucketName string `json:"bucketName"` } -// Auth holds the authentication configuration details. -type Auth struct { - // SecretRef specifies the reference to the Kubernetes secret containing authentication details. - SecretRef SecretRef `json:"secretRef"` -} - -// SecretRef contains the reference to a Kubernetes secret. -type SecretRef struct { - // Name specifies the name of the secret. - Name string `json:"name"` - - // Namespace specifies the namespace of the secret. - Namespace string `json:"namespace,omitempty"` -} - // IRSASetupStatus defines the observed state of IRSASetup type IRSASetupStatus struct { SelfHostedSetup []metav1.Condition `json:"selfHostedSetup,omitempty"` diff --git a/api/v1alpha1/zz_generated.deepcopy.go b/api/v1alpha1/zz_generated.deepcopy.go index fcbbf51..cbf5a8a 100644 --- a/api/v1alpha1/zz_generated.deepcopy.go +++ b/api/v1alpha1/zz_generated.deepcopy.go @@ -25,22 +25,6 @@ import ( runtime "k8s.io/apimachinery/pkg/runtime" ) -// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. -func (in *Auth) DeepCopyInto(out *Auth) { - *out = *in - out.SecretRef = in.SecretRef -} - -// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Auth. -func (in *Auth) DeepCopy() *Auth { - if in == nil { - return nil - } - out := new(Auth) - in.DeepCopyInto(out) - return out -} - // DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. func (in *Discovery) DeepCopyInto(out *Discovery) { *out = *in @@ -199,7 +183,6 @@ func (in *IRSASetupList) DeepCopyObject() runtime.Object { func (in *IRSASetupSpec) DeepCopyInto(out *IRSASetupSpec) { *out = *in out.Discovery = in.Discovery - out.Auth = in.Auth } // DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new IRSASetupSpec. @@ -307,18 +290,3 @@ func (in *S3Discovery) DeepCopy() *S3Discovery { in.DeepCopyInto(out) return out } - -// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. -func (in *SecretRef) DeepCopyInto(out *SecretRef) { - *out = *in -} - -// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SecretRef. -func (in *SecretRef) DeepCopy() *SecretRef { - if in == nil { - return nil - } - out := new(SecretRef) - in.DeepCopyInto(out) - return out -} diff --git a/config/crd/bases/irsa.kkb0318.github.io_irsasetups.yaml b/config/crd/bases/irsa.kkb0318.github.io_irsasetups.yaml index 41c75e0..7632366 100644 --- a/config/crd/bases/irsa.kkb0318.github.io_irsasetups.yaml +++ b/config/crd/bases/irsa.kkb0318.github.io_irsasetups.yaml @@ -44,25 +44,6 @@ spec: spec: description: IRSASetupSpec defines the desired state of IRSASetup properties: - auth: - description: Auth contains authentication configuration details. - properties: - secretRef: - description: SecretRef specifies the reference to the Kubernetes - secret containing authentication details. - properties: - name: - description: Name specifies the name of the secret. - type: string - namespace: - description: Namespace specifies the namespace of the secret. - type: string - required: - - name - type: object - required: - - secretRef - type: object cleanup: description: |- Cleanup, when enabled, allows the IRSASetup to perform garbage collection diff --git a/docs/api.md b/docs/api.md index 89eebd7..ac9155d 100644 --- a/docs/api.md +++ b/docs/api.md @@ -14,22 +14,6 @@ Package v1alpha1 contains API Schema definitions for the irsa v1alpha1 API group -#### Auth - - - -Auth holds the authentication configuration details. - - - -_Appears in:_ -- [IRSASetupSpec](#irsasetupspec) - -| Field | Description | Default | Validation | -| --- | --- | --- | --- | -| `secretRef` _[SecretRef](#secretref)_ | SecretRef specifies the reference to the Kubernetes secret containing authentication details. | | | - - #### Discovery @@ -118,7 +102,6 @@ _Appears in:_ | `cleanup` _boolean_ | Cleanup, when enabled, allows the IRSASetup to perform garbage collection
of resources that are no longer needed or managed. | | | | `mode` _string_ | Mode specifies the mode of operation. Can be either "selfhosted" or "eks". | | | | `discovery` _[Discovery](#discovery)_ | Discovery configures the IdP Discovery process, essential for setting up IRSA by locating
the OIDC provider information. | | | -| `auth` _[Auth](#auth)_ | Auth contains authentication configuration details. | | | @@ -177,22 +160,5 @@ _Appears in:_ | `bucketName` _string_ | BucketName is the name of the S3 bucket that hosts the OIDC discovery information. | | | -#### SecretRef - - - -SecretRef contains the reference to a Kubernetes secret. - - - -_Appears in:_ -- [Auth](#auth) - -| Field | Description | Default | Validation | -| --- | --- | --- | --- | -| `name` _string_ | Name specifies the name of the secret. | | | -| `namespace` _string_ | Namespace specifies the namespace of the secret. | | | - -