mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
force update if the selfhosted process ends midway
This commit is contained in:
@@ -81,7 +81,7 @@ func (in *IRSASetup) GetSelfhostedStatusConditions() *[]metav1.Condition {
|
|||||||
return &in.Status.SelfHostedSetup
|
return &in.Status.SelfHostedSetup
|
||||||
}
|
}
|
||||||
|
|
||||||
func IRSASetupSelfHostedReady(irsa IRSASetup, reason, message string) IRSASetup {
|
func SetupSelfHostedStatusReady(irsa IRSASetup, reason, message string) IRSASetup {
|
||||||
newCondition := metav1.Condition{
|
newCondition := metav1.Condition{
|
||||||
Type: meta.ReadyCondition,
|
Type: meta.ReadyCondition,
|
||||||
Status: metav1.ConditionTrue,
|
Status: metav1.ConditionTrue,
|
||||||
@@ -92,7 +92,7 @@ func IRSASetupSelfHostedReady(irsa IRSASetup, reason, message string) IRSASetup
|
|||||||
return irsa
|
return irsa
|
||||||
}
|
}
|
||||||
|
|
||||||
func IRSASetupSelfHostedNotReady(irsa IRSASetup, reason, message string) IRSASetup {
|
func SelfHostedStatusNotReady(irsa IRSASetup, reason, message string) IRSASetup {
|
||||||
newCondition := metav1.Condition{
|
newCondition := metav1.Condition{
|
||||||
Type: meta.ReadyCondition,
|
Type: meta.ReadyCondition,
|
||||||
Status: metav1.ConditionFalse,
|
Status: metav1.ConditionFalse,
|
||||||
@@ -103,15 +103,27 @@ func IRSASetupSelfHostedNotReady(irsa IRSASetup, reason, message string) IRSASet
|
|||||||
return irsa
|
return irsa
|
||||||
}
|
}
|
||||||
|
|
||||||
// IRSASetupSelfHostedReadyStatus
|
// SelfHostedReadyStatus
|
||||||
func IRSASetupSelfHostedReadyStatus(irsa IRSASetup) *metav1.Condition {
|
func SelfHostedReadyStatus(irsa IRSASetup) *metav1.Condition {
|
||||||
if c := apimeta.FindStatusCondition(irsa.Status.SelfHostedSetup, meta.ReadyCondition); c != nil {
|
if c := apimeta.FindStatusCondition(irsa.Status.SelfHostedSetup, meta.ReadyCondition); c != nil {
|
||||||
// return c, c.Status == metav1.ConditionTrue
|
|
||||||
return c
|
return c
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// HasConditionReason
|
||||||
|
func HasConditionReason(cond *metav1.Condition, reasons ...string) bool {
|
||||||
|
if cond == nil {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
for _, reason := range reasons {
|
||||||
|
if cond.Reason == reason {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
|
||||||
func IsSelfHostedReadyConditionTrue(irsa IRSASetup) bool {
|
func IsSelfHostedReadyConditionTrue(irsa IRSASetup) bool {
|
||||||
return apimeta.IsStatusConditionTrue(irsa.Status.SelfHostedSetup, meta.ReadyCondition)
|
return apimeta.IsStatusConditionTrue(irsa.Status.SelfHostedSetup, meta.ReadyCondition)
|
||||||
}
|
}
|
||||||
@@ -121,6 +133,7 @@ type SelfHostedReason string
|
|||||||
const (
|
const (
|
||||||
SelfHostedReasonFailedOidc SelfHostedReason = "SelfHostedSetupFailedOidcCreation"
|
SelfHostedReasonFailedOidc SelfHostedReason = "SelfHostedSetupFailedOidcCreation"
|
||||||
SelfHostedReasonFailedKeys SelfHostedReason = "SelfHostedSetupFailedKeysCreation"
|
SelfHostedReasonFailedKeys SelfHostedReason = "SelfHostedSetupFailedKeysCreation"
|
||||||
|
SelfHostedReasonReady SelfHostedReason = "SelfHostedSetupReady"
|
||||||
)
|
)
|
||||||
|
|
||||||
//+kubebuilder:object:root=true
|
//+kubebuilder:object:root=true
|
||||||
|
|||||||
@@ -118,3 +118,5 @@ _Appears in:_
|
|||||||
| `namespace` _string_ | Namespace specifies the namespace of the secret. | | |
|
| `namespace` _string_ | Namespace specifies the namespace of the secret. | | |
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
+30
-7
@@ -85,17 +85,31 @@ func (a *AwsS3Client) CheckObjectExists(ctx context.Context, key string) (bool,
|
|||||||
return true, nil
|
return true, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
type ObjectInput struct {
|
||||||
|
Key string
|
||||||
|
Body []byte
|
||||||
|
}
|
||||||
|
|
||||||
|
func (a *AwsS3Client) CreateObjectsPublic(ctx context.Context, inputs []ObjectInput) error {
|
||||||
|
for _, input := range inputs {
|
||||||
|
if err := a.CreateObjectPublic(ctx, input); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
// CreateObjectPublic creates a file to an S3 bucket and sets its access level to public read.
|
// CreateObjectPublic creates a file to an S3 bucket and sets its access level to public read.
|
||||||
// This means the file can be read by anyone on the internet.
|
// This means the file can be read by anyone on the internet.
|
||||||
func (a *AwsS3Client) CreateObjectPublic(ctx context.Context, key string, body []byte) error {
|
func (a *AwsS3Client) CreateObjectPublic(ctx context.Context, input ObjectInput) error {
|
||||||
exists, err := a.CheckObjectExists(ctx, key)
|
exists, err := a.CheckObjectExists(ctx, input.Key)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
if exists {
|
if exists {
|
||||||
log.Printf("skipped to create bucket object %s \n", key)
|
log.Printf("skipped to create bucket object %s \n", input.Key)
|
||||||
} else {
|
} else {
|
||||||
err := a.PutObjectPublic(ctx, key, body)
|
err := a.PutObjectPublic(ctx, input)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -103,14 +117,23 @@ func (a *AwsS3Client) CreateObjectPublic(ctx context.Context, key string, body [
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (a *AwsS3Client) PutObjectsPublic(ctx context.Context, inputs []ObjectInput) error {
|
||||||
|
for _, input := range inputs {
|
||||||
|
if err := a.PutObjectPublic(ctx, input); err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
// PutObjectPublic uploads a file to an S3 bucket and sets its access level to public read.
|
// PutObjectPublic uploads a file to an S3 bucket and sets its access level to public read.
|
||||||
// This means the file can be read by anyone on the internet.
|
// This means the file can be read by anyone on the internet.
|
||||||
func (a *AwsS3Client) PutObjectPublic(ctx context.Context, key string, body []byte) error {
|
func (a *AwsS3Client) PutObjectPublic(ctx context.Context, input ObjectInput) error {
|
||||||
_, err := a.Client.PutObject(ctx, &s3.PutObjectInput{
|
_, err := a.Client.PutObject(ctx, &s3.PutObjectInput{
|
||||||
Bucket: aws.String(a.bucketName),
|
Bucket: aws.String(a.bucketName),
|
||||||
Key: aws.String(key),
|
Key: aws.String(input.Key),
|
||||||
ACL: types.ObjectCannedACLPublicRead,
|
ACL: types.ObjectCannedACLPublicRead,
|
||||||
Body: bytes.NewReader(body),
|
Body: bytes.NewReader(input.Body),
|
||||||
ContentType: aws.String("application/json"),
|
ContentType: aws.String("application/json"),
|
||||||
})
|
})
|
||||||
return err
|
return err
|
||||||
|
|||||||
@@ -18,7 +18,6 @@ package controller
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
|
||||||
|
|
||||||
"k8s.io/apimachinery/pkg/runtime"
|
"k8s.io/apimachinery/pkg/runtime"
|
||||||
ctrl "sigs.k8s.io/controller-runtime"
|
ctrl "sigs.k8s.io/controller-runtime"
|
||||||
@@ -154,32 +153,32 @@ func reconcileSelfhosted(ctx context.Context, obj *irsav1alpha1.IRSASetup, awsCl
|
|||||||
var reason irsav1alpha1.SelfHostedReason
|
var reason irsav1alpha1.SelfHostedReason
|
||||||
defer func() {
|
defer func() {
|
||||||
if e != nil {
|
if e != nil {
|
||||||
*obj = irsav1alpha1.IRSASetupSelfHostedNotReady(*obj, string(reason), e.Error())
|
*obj = irsav1alpha1.SelfHostedStatusNotReady(*obj, string(reason), e.Error())
|
||||||
}
|
}
|
||||||
}()
|
}()
|
||||||
|
|
||||||
var forceUpdate bool
|
forceUpdate := irsav1alpha1.HasConditionReason(
|
||||||
condition := irsav1alpha1.IRSASetupSelfHostedReadyStatus(*obj)
|
irsav1alpha1.SelfHostedReadyStatus(*obj),
|
||||||
switch irsav1alpha1.SelfHostedReason(condition.Reason) {
|
string(irsav1alpha1.SelfHostedReasonFailedKeys),
|
||||||
case irsav1alpha1.SelfHostedReasonFailedKeys, irsav1alpha1.SelfHostedReasonFailedOidc:
|
string(irsav1alpha1.SelfHostedReasonFailedOidc),
|
||||||
forceUpdate = true
|
)
|
||||||
default:
|
err = selfhosted.Execute(ctx, factory, forceUpdate)
|
||||||
forceUpdate = false
|
|
||||||
}
|
|
||||||
fmt.Println(forceUpdate) // TODO: force Update logic
|
|
||||||
err = selfhosted.Execute(ctx, factory)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
e = err
|
e = err
|
||||||
reason = irsav1alpha1.SelfHostedReasonFailedOidc
|
reason = irsav1alpha1.SelfHostedReasonFailedOidc
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
if forceUpdate {
|
||||||
|
err = kubeHandler.ApplyAll(ctx)
|
||||||
|
} else {
|
||||||
err = kubeHandler.CreateAll(ctx)
|
err = kubeHandler.CreateAll(ctx)
|
||||||
|
}
|
||||||
if err != nil {
|
if err != nil {
|
||||||
e = err
|
e = err
|
||||||
reason = irsav1alpha1.SelfHostedReasonFailedKeys
|
reason = irsav1alpha1.SelfHostedReasonFailedKeys
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
*obj = irsav1alpha1.IRSASetupSelfHostedReady(*obj, "SelfHostedSetupReady", e.Error())
|
*obj = irsav1alpha1.SetupSelfHostedStatusReady(*obj, string(irsav1alpha1.SelfHostedReasonReady), "successfully setup resources for self-hosted")
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ type OIDCIdPDiscoveryContents interface {
|
|||||||
|
|
||||||
type OIDCIdPDiscovery interface {
|
type OIDCIdPDiscovery interface {
|
||||||
CreateStorage(ctx context.Context) error
|
CreateStorage(ctx context.Context) error
|
||||||
Upload(ctx context.Context, o OIDCIdPDiscoveryContents) error
|
Upload(ctx context.Context, o OIDCIdPDiscoveryContents, forceUpdate bool) error
|
||||||
Delete(ctx context.Context, o OIDCIdPDiscoveryContents) error
|
Delete(ctx context.Context, o OIDCIdPDiscoveryContents) error
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -32,30 +32,32 @@ func (s *S3IdPDiscovery) CreateStorage(ctx context.Context) error {
|
|||||||
|
|
||||||
// Upload uploads the OIDC provider's discovery configuration and JSON Web Key Set (JWKS) to the specified AWS S3 bucket.
|
// Upload uploads the OIDC provider's discovery configuration and JSON Web Key Set (JWKS) to the specified AWS S3 bucket.
|
||||||
// This method is responsible for uploading the necessary OIDC configuration files to S3, making them accessible for OIDC clients.
|
// This method is responsible for uploading the necessary OIDC configuration files to S3, making them accessible for OIDC clients.
|
||||||
func (s *S3IdPDiscovery) Upload(ctx context.Context, o selfhosted.OIDCIdPDiscoveryContents) error {
|
func (s *S3IdPDiscovery) Upload(ctx context.Context, o selfhosted.OIDCIdPDiscoveryContents, forceUpdate bool) error {
|
||||||
discovery, err := o.Discovery()
|
discovery, err := o.Discovery()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
err = s.s3Client.CreateObjectPublic(ctx,
|
|
||||||
CONFIGURATION_PATH,
|
|
||||||
discovery,
|
|
||||||
)
|
|
||||||
if err != nil {
|
|
||||||
return fmt.Errorf("unable to upload discovery document, %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Uplaod JWK
|
|
||||||
jwk, err := o.JWK()
|
jwk, err := o.JWK()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
err = s.s3Client.CreateObjectPublic(ctx,
|
inputs := []client.ObjectInput{
|
||||||
o.JWKsFileName(),
|
{
|
||||||
jwk,
|
Key: CONFIGURATION_PATH,
|
||||||
)
|
Body: discovery,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Key: o.JWKsFileName(),
|
||||||
|
Body: jwk,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
if forceUpdate {
|
||||||
|
err = s.s3Client.PutObjectsPublic(ctx, inputs)
|
||||||
|
} else {
|
||||||
|
err = s.s3Client.CreateObjectsPublic(ctx, inputs)
|
||||||
|
}
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("unable to upload JWK, %w", err)
|
return fmt.Errorf("unable to upload object, %w", err)
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,7 +2,7 @@ package selfhosted
|
|||||||
|
|
||||||
import "context"
|
import "context"
|
||||||
|
|
||||||
func Execute(ctx context.Context, factory OIDCIdPFactory) error {
|
func Execute(ctx context.Context, factory OIDCIdPFactory, forceUpdate bool) error {
|
||||||
issuerMeta := factory.IssuerMeta()
|
issuerMeta := factory.IssuerMeta()
|
||||||
discovery := factory.IdPDiscovery()
|
discovery := factory.IdPDiscovery()
|
||||||
discoveryContents := factory.IdPDiscoveryContents(issuerMeta)
|
discoveryContents := factory.IdPDiscoveryContents(issuerMeta)
|
||||||
@@ -14,7 +14,7 @@ func Execute(ctx context.Context, factory OIDCIdPFactory) error {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
err = discovery.Upload(ctx, discoveryContents)
|
err = discovery.Upload(ctx, discoveryContents, forceUpdate)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user