mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
modify unused apis, fix docs
This commit is contained in:
@@ -67,7 +67,10 @@ spec:
|
|||||||
|
|
||||||
Check the IRSASetup custom resource status to verify whether it is set to true.
|
Check the IRSASetup custom resource status to verify whether it is set to true.
|
||||||
|
|
||||||
5. Modify kube-apiserver Settings
|
> [!NOTE]
|
||||||
|
> Please ensure that only one IRSASetup resource is created.
|
||||||
|
|
||||||
|
4. Modify kube-apiserver Settings
|
||||||
|
|
||||||
If the IRSASetup status is true, a key file (Name: `irsa-manager-key` , Namespace: `kube-system` ) will be created. This is used for signing tokens in the kubernetes API.
|
If the IRSASetup status is true, a key file (Name: `irsa-manager-key` , Namespace: `kube-system` ) will be created. This is used for signing tokens in the kubernetes API.
|
||||||
Execute the following commands on the control plane server to save the public and private keys locally for Kubernetes signatures:
|
Execute the following commands on the control plane server to save the public and private keys locally for Kubernetes signatures:
|
||||||
|
|||||||
@@ -39,9 +39,6 @@ type IRSASetupSpec struct {
|
|||||||
// Discovery configures the IdP Discovery process, essential for setting up IRSA by locating
|
// Discovery configures the IdP Discovery process, essential for setting up IRSA by locating
|
||||||
// the OIDC provider information.
|
// the OIDC provider information.
|
||||||
Discovery Discovery `json:"discovery"`
|
Discovery Discovery `json:"discovery"`
|
||||||
|
|
||||||
// Auth contains authentication configuration details.
|
|
||||||
Auth Auth `json:"auth,omitempty"`
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Discovery holds the configuration for IdP Discovery, which is crucial for locating
|
// Discovery holds the configuration for IdP Discovery, which is crucial for locating
|
||||||
@@ -60,21 +57,6 @@ type S3Discovery struct {
|
|||||||
BucketName string `json:"bucketName"`
|
BucketName string `json:"bucketName"`
|
||||||
}
|
}
|
||||||
|
|
||||||
// Auth holds the authentication configuration details.
|
|
||||||
type Auth struct {
|
|
||||||
// SecretRef specifies the reference to the Kubernetes secret containing authentication details.
|
|
||||||
SecretRef SecretRef `json:"secretRef"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// SecretRef contains the reference to a Kubernetes secret.
|
|
||||||
type SecretRef struct {
|
|
||||||
// Name specifies the name of the secret.
|
|
||||||
Name string `json:"name"`
|
|
||||||
|
|
||||||
// Namespace specifies the namespace of the secret.
|
|
||||||
Namespace string `json:"namespace,omitempty"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// IRSASetupStatus defines the observed state of IRSASetup
|
// IRSASetupStatus defines the observed state of IRSASetup
|
||||||
type IRSASetupStatus struct {
|
type IRSASetupStatus struct {
|
||||||
SelfHostedSetup []metav1.Condition `json:"selfHostedSetup,omitempty"`
|
SelfHostedSetup []metav1.Condition `json:"selfHostedSetup,omitempty"`
|
||||||
|
|||||||
@@ -25,22 +25,6 @@ import (
|
|||||||
runtime "k8s.io/apimachinery/pkg/runtime"
|
runtime "k8s.io/apimachinery/pkg/runtime"
|
||||||
)
|
)
|
||||||
|
|
||||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
|
||||||
func (in *Auth) DeepCopyInto(out *Auth) {
|
|
||||||
*out = *in
|
|
||||||
out.SecretRef = in.SecretRef
|
|
||||||
}
|
|
||||||
|
|
||||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Auth.
|
|
||||||
func (in *Auth) DeepCopy() *Auth {
|
|
||||||
if in == nil {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
out := new(Auth)
|
|
||||||
in.DeepCopyInto(out)
|
|
||||||
return out
|
|
||||||
}
|
|
||||||
|
|
||||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||||
func (in *Discovery) DeepCopyInto(out *Discovery) {
|
func (in *Discovery) DeepCopyInto(out *Discovery) {
|
||||||
*out = *in
|
*out = *in
|
||||||
@@ -199,7 +183,6 @@ func (in *IRSASetupList) DeepCopyObject() runtime.Object {
|
|||||||
func (in *IRSASetupSpec) DeepCopyInto(out *IRSASetupSpec) {
|
func (in *IRSASetupSpec) DeepCopyInto(out *IRSASetupSpec) {
|
||||||
*out = *in
|
*out = *in
|
||||||
out.Discovery = in.Discovery
|
out.Discovery = in.Discovery
|
||||||
out.Auth = in.Auth
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new IRSASetupSpec.
|
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new IRSASetupSpec.
|
||||||
@@ -307,18 +290,3 @@ func (in *S3Discovery) DeepCopy() *S3Discovery {
|
|||||||
in.DeepCopyInto(out)
|
in.DeepCopyInto(out)
|
||||||
return out
|
return out
|
||||||
}
|
}
|
||||||
|
|
||||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
|
||||||
func (in *SecretRef) DeepCopyInto(out *SecretRef) {
|
|
||||||
*out = *in
|
|
||||||
}
|
|
||||||
|
|
||||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SecretRef.
|
|
||||||
func (in *SecretRef) DeepCopy() *SecretRef {
|
|
||||||
if in == nil {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
out := new(SecretRef)
|
|
||||||
in.DeepCopyInto(out)
|
|
||||||
return out
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -44,25 +44,6 @@ spec:
|
|||||||
spec:
|
spec:
|
||||||
description: IRSASetupSpec defines the desired state of IRSASetup
|
description: IRSASetupSpec defines the desired state of IRSASetup
|
||||||
properties:
|
properties:
|
||||||
auth:
|
|
||||||
description: Auth contains authentication configuration details.
|
|
||||||
properties:
|
|
||||||
secretRef:
|
|
||||||
description: SecretRef specifies the reference to the Kubernetes
|
|
||||||
secret containing authentication details.
|
|
||||||
properties:
|
|
||||||
name:
|
|
||||||
description: Name specifies the name of the secret.
|
|
||||||
type: string
|
|
||||||
namespace:
|
|
||||||
description: Namespace specifies the namespace of the secret.
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- name
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- secretRef
|
|
||||||
type: object
|
|
||||||
cleanup:
|
cleanup:
|
||||||
description: |-
|
description: |-
|
||||||
Cleanup, when enabled, allows the IRSASetup to perform garbage collection
|
Cleanup, when enabled, allows the IRSASetup to perform garbage collection
|
||||||
|
|||||||
-34
@@ -14,22 +14,6 @@ Package v1alpha1 contains API Schema definitions for the irsa v1alpha1 API group
|
|||||||
|
|
||||||
|
|
||||||
|
|
||||||
#### Auth
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
Auth holds the authentication configuration details.
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
_Appears in:_
|
|
||||||
- [IRSASetupSpec](#irsasetupspec)
|
|
||||||
|
|
||||||
| Field | Description | Default | Validation |
|
|
||||||
| --- | --- | --- | --- |
|
|
||||||
| `secretRef` _[SecretRef](#secretref)_ | SecretRef specifies the reference to the Kubernetes secret containing authentication details. | | |
|
|
||||||
|
|
||||||
|
|
||||||
#### Discovery
|
#### Discovery
|
||||||
|
|
||||||
|
|
||||||
@@ -118,7 +102,6 @@ _Appears in:_
|
|||||||
| `cleanup` _boolean_ | Cleanup, when enabled, allows the IRSASetup to perform garbage collection<br />of resources that are no longer needed or managed. | | |
|
| `cleanup` _boolean_ | Cleanup, when enabled, allows the IRSASetup to perform garbage collection<br />of resources that are no longer needed or managed. | | |
|
||||||
| `mode` _string_ | Mode specifies the mode of operation. Can be either "selfhosted" or "eks". | | |
|
| `mode` _string_ | Mode specifies the mode of operation. Can be either "selfhosted" or "eks". | | |
|
||||||
| `discovery` _[Discovery](#discovery)_ | Discovery configures the IdP Discovery process, essential for setting up IRSA by locating<br />the OIDC provider information. | | |
|
| `discovery` _[Discovery](#discovery)_ | Discovery configures the IdP Discovery process, essential for setting up IRSA by locating<br />the OIDC provider information. | | |
|
||||||
| `auth` _[Auth](#auth)_ | Auth contains authentication configuration details. | | |
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
@@ -177,22 +160,5 @@ _Appears in:_
|
|||||||
| `bucketName` _string_ | BucketName is the name of the S3 bucket that hosts the OIDC discovery information. | | |
|
| `bucketName` _string_ | BucketName is the name of the S3 bucket that hosts the OIDC discovery information. | | |
|
||||||
|
|
||||||
|
|
||||||
#### SecretRef
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
SecretRef contains the reference to a Kubernetes secret.
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
_Appears in:_
|
|
||||||
- [Auth](#auth)
|
|
||||||
|
|
||||||
| Field | Description | Default | Validation |
|
|
||||||
| --- | --- | --- | --- |
|
|
||||||
| `name` _string_ | Name specifies the name of the secret. | | |
|
|
||||||
| `namespace` _string_ | Namespace specifies the namespace of the secret. | | |
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user