fix group name

This commit is contained in:
kkb0318
2024-06-02 15:04:38 +09:00
parent da13a71532
commit 979d08e695
21 changed files with 803 additions and 465 deletions
+2 -2
View File
@@ -55,7 +55,7 @@ kubectl create secret generic aws-secret -n irsa-manager-system \
Define and apply an IRSASetup custom resource according to your needs. Define and apply an IRSASetup custom resource according to your needs.
```yaml ```yaml
apiVersion: irsa.kkb0318.github.io/v1alpha1 apiVersion: irsa-manager.kkb0318.github.io/v1alpha1
kind: IRSASetup kind: IRSASetup
metadata: metadata:
name: irsa-init name: irsa-init
@@ -135,7 +135,7 @@ You can set IRSA for the Kubernetes ServiceAccount.
The following example shows that irsa-manager sets the `irsa1-sa` ServiceAccount in the kube-system and default namespaces with the AmazonS3FullAccess policy: The following example shows that irsa-manager sets the `irsa1-sa` ServiceAccount in the kube-system and default namespaces with the AmazonS3FullAccess policy:
```yaml ```yaml
apiVersion: irsa.kkb0318.github.io/v1alpha1 apiVersion: irsa-manager.kkb0318.github.io/v1alpha1
kind: IRSA kind: IRSA
metadata: metadata:
name: irsa-sample name: irsa-sample
+2 -2
View File
@@ -16,7 +16,7 @@ limitations under the License.
// Package v1alpha1 contains API Schema definitions for the irsa v1alpha1 API group // Package v1alpha1 contains API Schema definitions for the irsa v1alpha1 API group
// +kubebuilder:object:generate=true // +kubebuilder:object:generate=true
// +groupName=irsa.kkb0318.github.io // +groupName=irsa-manager.kkb0318.github.io
package v1alpha1 package v1alpha1
import ( import (
@@ -26,7 +26,7 @@ import (
var ( var (
// GroupVersion is group version used to register these objects // GroupVersion is group version used to register these objects
GroupVersion = schema.GroupVersion{Group: "irsa.kkb0318.github.io", Version: "v1alpha1"} GroupVersion = schema.GroupVersion{Group: "irsa-manager.kkb0318.github.io", Version: "v1alpha1"}
// SchemeBuilder is used to add go types to the GroupVersionKind scheme // SchemeBuilder is used to add go types to the GroupVersionKind scheme
SchemeBuilder = &scheme.Builder{GroupVersion: GroupVersion} SchemeBuilder = &scheme.Builder{GroupVersion: GroupVersion}
+91 -85
View File
@@ -3,9 +3,9 @@ kind: CustomResourceDefinition
metadata: metadata:
annotations: annotations:
controller-gen.kubebuilder.io/version: v0.14.0 controller-gen.kubebuilder.io/version: v0.14.0
name: irsasetups.irsa.kkb0318.github.io name: irsasetups.irsa-manager.kkb0318.github.io
spec: spec:
group: irsa.kkb0318.github.io group: irsa-manager.kkb0318.github.io
names: names:
kind: IRSASetup kind: IRSASetup
listKind: IRSASetupList listKind: IRSASetupList
@@ -13,86 +13,92 @@ spec:
singular: irsasetup singular: irsasetup
scope: Namespaced scope: Namespaced
versions: versions:
- name: v1alpha1 - name: v1alpha1
schema: schema:
openAPIV3Schema: openAPIV3Schema:
description: IRSASetup represents a configuration for setting up IAM Roles description:
for Service Accounts (IRSA) in a Kubernetes cluster. IRSASetup represents a configuration for setting up IAM Roles
properties: for Service Accounts (IRSA) in a Kubernetes cluster.
apiVersion: properties:
description: |- apiVersion:
APIVersion defines the versioned schema of this representation of an object. description: |-
Servers should convert recognized schemas to the latest internal value, and APIVersion defines the versioned schema of this representation of an object.
may reject unrecognized values. Servers should convert recognized schemas to the latest internal value, and
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources may reject unrecognized values.
type: string More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind: type: string
description: |- kind:
Kind is a string value representing the REST resource this object represents. description: |-
Servers may infer this from the endpoint the client submits requests to. Kind is a string value representing the REST resource this object represents.
Cannot be updated. Servers may infer this from the endpoint the client submits requests to.
In CamelCase. Cannot be updated.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds In CamelCase.
type: string More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata: type: string
type: object metadata:
spec: type: object
description: IRSASetupSpec defines the desired state of IRSASetup spec:
properties: description: IRSASetupSpec defines the desired state of IRSASetup
auth: properties:
description: Auth contains authentication configuration details. auth:
properties: description: Auth contains authentication configuration details.
secretRef: properties:
description: SecretRef specifies the reference to the Kubernetes secretRef:
secret containing authentication details. description:
properties: SecretRef specifies the reference to the Kubernetes
name: secret containing authentication details.
description: Name specifies the name of the secret. properties:
type: string name:
namespace: description: Name specifies the name of the secret.
description: Namespace specifies the namespace of the secret. type: string
type: string namespace:
required: description: Namespace specifies the namespace of the secret.
- name type: string
type: object required:
required: - name
- secretRef type: object
type: object required:
discovery: - secretRef
description: |- type: object
Discovery configures the IdP Discovery process, essential for setting up IRSA by locating discovery:
the OIDC provider information. description: |-
properties: Discovery configures the IdP Discovery process, essential for setting up IRSA by locating
s3: the OIDC provider information.
description: S3 specifies the AWS S3 bucket details where the properties:
OIDC provider's discovery information is hosted. s3:
properties: description:
bucketName: S3 specifies the AWS S3 bucket details where the
description: BucketName is the name of the S3 bucket that OIDC provider's discovery information is hosted.
hosts the OIDC discovery information. properties:
type: string bucketName:
region: description:
description: Region denotes the AWS region where the S3 bucket BucketName is the name of the S3 bucket that
is located. hosts the OIDC discovery information.
type: string type: string
required: region:
- bucketName description:
- region Region denotes the AWS region where the S3 bucket
type: object is located.
type: object type: string
mode: required:
description: Mode specifies the mode of operation. Can be either "selfhosted" - bucketName
or "eks". - region
type: string type: object
required: type: object
- discovery mode:
- mode description:
type: object Mode specifies the mode of operation. Can be either "selfhosted"
status: or "eks".
description: IRSASetupStatus defines the observed state of IRSASetup type: string
type: object required:
type: object - discovery
served: true - mode
storage: true type: object
subresources: status:
status: {} description: IRSASetupStatus defines the observed state of IRSASetup
type: object
type: object
served: true
storage: true
subresources:
status: {}
@@ -6,7 +6,7 @@ metadata:
{{- include "irsa-manager.labels" . | nindent 4 }} {{- include "irsa-manager.labels" . | nindent 4 }}
rules: rules:
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsasetups - irsasetups
verbs: verbs:
@@ -18,13 +18,13 @@ rules:
- update - update
- watch - watch
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsasetups/finalizers - irsasetups/finalizers
verbs: verbs:
- update - update
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsasetups/status - irsasetups/status
verbs: verbs:
@@ -48,4 +48,4 @@ roleRef:
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: '{{ include "irsa-manager.fullname" . }}-controller-manager' name: '{{ include "irsa-manager.fullname" . }}-controller-manager'
namespace: '{{ .Release.Namespace }}' namespace: '{{ .Release.Namespace }}'
@@ -0,0 +1,161 @@
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.14.0
name: irsas.irsa-manager.kkb0318.github.io
spec:
group: irsa-manager.kkb0318.github.io
names:
kind: IRSA
listKind: IRSAList
plural: irsas
singular: irsa
scope: Namespaced
versions:
- additionalPrinterColumns:
- jsonPath: .status.conditions[?(@.type=="Ready")].status
name: Ready
type: string
name: v1alpha1
schema:
openAPIV3Schema:
description: IRSA is the Schema for the irsas API
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
description: IRSASpec defines the desired state of IRSA
properties:
cleanup:
description: |-
Cleanup, when enabled, allows the IRSA to perform garbage collection
of resources that are no longer needed or managed.
type: boolean
iamPolicies:
description: |-
IamPolicies represents the list of IAM policies to be attached to the IAM role.
You can set both the policy name (only AWS default policies) or the full ARN.
items:
type: string
type: array
iamRole:
description: IamRole represents the IAM role details associated with
the IRSA.
properties:
name:
description: Name represents the name of the IAM role.
type: string
type: object
serviceAccount:
description: ServiceAccount represents the Kubernetes service account
associated with the IRSA.
properties:
name:
description: Name represents the name of the Kubernetes service
account
type: string
namespaces:
description: Namespaces represents the list of namespaces where
the service account is used
items:
type: string
type: array
type: object
required:
- cleanup
type: object
status:
description: IRSAStatus defines the observed state of IRSA.
properties:
conditions:
items:
description: "Condition contains details for one aspect of the current
state of this API Resource.\n---\nThis struct is intended for
direct use as an array at the field path .status.conditions. For
example,\n\n\n\ttype FooStatus struct{\n\t // Represents the
observations of a foo's current state.\n\t // Known .status.conditions.type
are: \"Available\", \"Progressing\", and \"Degraded\"\n\t //
+patchMergeKey=type\n\t // +patchStrategy=merge\n\t // +listType=map\n\t
\ // +listMapKey=type\n\t Conditions []metav1.Condition `json:\"conditions,omitempty\"
patchStrategy:\"merge\" patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t
\ // other fields\n\t}"
properties:
lastTransitionTime:
description: |-
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string
message:
description: |-
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength: 32768
type: string
observedGeneration:
description: |-
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format: int64
minimum: 0
type: integer
reason:
description: |-
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
type: string
status:
description: status of the condition, one of True, False, Unknown.
enum:
- "True"
- "False"
- Unknown
type: string
type:
description: |-
type of condition in CamelCase or in foo.example.com/CamelCase.
---
Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
useful (see .node.status.conditions), the ability to deconflict is important.
The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
type: array
type: object
type: object
served: true
storage: true
subresources:
status: {}
@@ -0,0 +1,160 @@
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.14.0
name: irsasetups.irsa-manager.kkb0318.github.io
spec:
group: irsa-manager.kkb0318.github.io
names:
kind: IRSASetup
listKind: IRSASetupList
plural: irsasetups
singular: irsasetup
scope: Namespaced
versions:
- additionalPrinterColumns:
- jsonPath: .status.selfHostedSetup[?(@.type=="Ready")].status
name: SelfHostedReady
type: string
name: v1alpha1
schema:
openAPIV3Schema:
description: IRSASetup represents a configuration for setting up IAM Roles
for Service Accounts (IRSA) in a Kubernetes cluster.
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
description: IRSASetupSpec defines the desired state of IRSASetup
properties:
cleanup:
description: |-
Cleanup, when enabled, allows the IRSASetup to perform garbage collection
of resources that are no longer needed or managed.
type: boolean
discovery:
description: |-
Discovery configures the IdP Discovery process, essential for setting up IRSA by locating
the OIDC provider information.
properties:
s3:
description: S3 specifies the AWS S3 bucket details where the
OIDC provider's discovery information is hosted.
properties:
bucketName:
description: BucketName is the name of the S3 bucket that
hosts the OIDC discovery information.
type: string
region:
description: Region denotes the AWS region where the S3 bucket
is located.
type: string
required:
- bucketName
- region
type: object
type: object
mode:
description: Mode specifies the mode of operation. Can be either "selfhosted"
or "eks".
type: string
required:
- cleanup
- discovery
- mode
type: object
status:
description: IRSASetupStatus defines the observed state of IRSASetup
properties:
selfHostedSetup:
items:
description: "Condition contains details for one aspect of the current
state of this API Resource.\n---\nThis struct is intended for
direct use as an array at the field path .status.conditions. For
example,\n\n\n\ttype FooStatus struct{\n\t // Represents the
observations of a foo's current state.\n\t // Known .status.conditions.type
are: \"Available\", \"Progressing\", and \"Degraded\"\n\t //
+patchMergeKey=type\n\t // +patchStrategy=merge\n\t // +listType=map\n\t
\ // +listMapKey=type\n\t Conditions []metav1.Condition `json:\"conditions,omitempty\"
patchStrategy:\"merge\" patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t
\ // other fields\n\t}"
properties:
lastTransitionTime:
description: |-
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string
message:
description: |-
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength: 32768
type: string
observedGeneration:
description: |-
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format: int64
minimum: 0
type: integer
reason:
description: |-
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
type: string
status:
description: status of the condition, one of True, False, Unknown.
enum:
- "True"
- "False"
- Unknown
type: string
type:
description: |-
type of condition in CamelCase or in foo.example.com/CamelCase.
---
Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
useful (see .node.status.conditions), the ability to deconflict is important.
The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
type: array
type: object
type: object
served: true
storage: true
subresources:
status: {}
+148 -143
View File
@@ -4,9 +4,9 @@ kind: CustomResourceDefinition
metadata: metadata:
annotations: annotations:
controller-gen.kubebuilder.io/version: v0.14.0 controller-gen.kubebuilder.io/version: v0.14.0
name: irsas.irsa.kkb0318.github.io name: irsas.irsa-manager.kkb0318.github.io
spec: spec:
group: irsa.kkb0318.github.io group: irsa-manager.kkb0318.github.io
names: names:
kind: IRSA kind: IRSA
listKind: IRSAList listKind: IRSAList
@@ -14,148 +14,153 @@ spec:
singular: irsa singular: irsa
scope: Namespaced scope: Namespaced
versions: versions:
- additionalPrinterColumns: - additionalPrinterColumns:
- jsonPath: .status.conditions[?(@.type=="Ready")].status - jsonPath: .status.conditions[?(@.type=="Ready")].status
name: Ready name: Ready
type: string type: string
name: v1alpha1 name: v1alpha1
schema: schema:
openAPIV3Schema: openAPIV3Schema:
description: IRSA is the Schema for the irsas API description: IRSA is the Schema for the irsas API
properties: properties:
apiVersion: apiVersion:
description: |- description: |-
APIVersion defines the versioned schema of this representation of an object. APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values. may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string type: string
kind: kind:
description: |- description: |-
Kind is a string value representing the REST resource this object represents. Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to. Servers may infer this from the endpoint the client submits requests to.
Cannot be updated. Cannot be updated.
In CamelCase. In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string type: string
metadata: metadata:
type: object type: object
spec: spec:
description: IRSASpec defines the desired state of IRSA description: IRSASpec defines the desired state of IRSA
properties: properties:
cleanup: cleanup:
description: |- description: |-
Cleanup, when enabled, allows the IRSA to perform garbage collection Cleanup, when enabled, allows the IRSA to perform garbage collection
of resources that are no longer needed or managed. of resources that are no longer needed or managed.
type: boolean type: boolean
iamPolicies: iamPolicies:
description: |- description: |-
IamPolicies represents the list of IAM policies to be attached to the IAM role. IamPolicies represents the list of IAM policies to be attached to the IAM role.
You can set both the policy name (only AWS default policies) or the full ARN. You can set both the policy name (only AWS default policies) or the full ARN.
items: items:
type: string
type: array
iamRole:
description: IamRole represents the IAM role details associated with
the IRSA.
properties:
name:
description: Name represents the name of the IAM role.
type: string type: string
type: object type: array
serviceAccount: iamRole:
description: ServiceAccount represents the Kubernetes service account description:
associated with the IRSA. IamRole represents the IAM role details associated with
properties: the IRSA.
name:
description: Name represents the name of the Kubernetes service
account
type: string
namespaces:
description: Namespaces represents the list of namespaces where
the service account is used
items:
type: string
type: array
type: object
required:
- cleanup
type: object
status:
description: IRSAStatus defines the observed state of IRSA.
properties:
conditions:
items:
description: "Condition contains details for one aspect of the current
state of this API Resource.\n---\nThis struct is intended for
direct use as an array at the field path .status.conditions. For
example,\n\n\n\ttype FooStatus struct{\n\t // Represents the
observations of a foo's current state.\n\t // Known .status.conditions.type
are: \"Available\", \"Progressing\", and \"Degraded\"\n\t //
+patchMergeKey=type\n\t // +patchStrategy=merge\n\t // +listType=map\n\t
\ // +listMapKey=type\n\t Conditions []metav1.Condition `json:\"conditions,omitempty\"
patchStrategy:\"merge\" patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t
\ // other fields\n\t}"
properties: properties:
lastTransitionTime: name:
description: |- description: Name represents the name of the IAM role.
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string type: string
message:
description: |-
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength: 32768
type: string
observedGeneration:
description: |-
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format: int64
minimum: 0
type: integer
reason:
description: |-
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
type: string
status:
description: status of the condition, one of True, False, Unknown.
enum:
- "True"
- "False"
- Unknown
type: string
type:
description: |-
type of condition in CamelCase or in foo.example.com/CamelCase.
---
Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
useful (see .node.status.conditions), the ability to deconflict is important.
The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object type: object
type: array serviceAccount:
type: object description:
type: object ServiceAccount represents the Kubernetes service account
served: true associated with the IRSA.
storage: true properties:
subresources: name:
status: {} description:
Name represents the name of the Kubernetes service
account
type: string
namespaces:
description:
Namespaces represents the list of namespaces where
the service account is used
items:
type: string
type: array
type: object
required:
- cleanup
type: object
status:
description: IRSAStatus defines the observed state of IRSA.
properties:
conditions:
items:
description:
"Condition contains details for one aspect of the current
state of this API Resource.\n---\nThis struct is intended for
direct use as an array at the field path .status.conditions. For
example,\n\n\n\ttype FooStatus struct{\n\t // Represents the
observations of a foo's current state.\n\t // Known .status.conditions.type
are: \"Available\", \"Progressing\", and \"Degraded\"\n\t //
+patchMergeKey=type\n\t // +patchStrategy=merge\n\t // +listType=map\n\t
\ // +listMapKey=type\n\t Conditions []metav1.Condition `json:\"conditions,omitempty\"
patchStrategy:\"merge\" patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t
\ // other fields\n\t}"
properties:
lastTransitionTime:
description: |-
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string
message:
description: |-
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength: 32768
type: string
observedGeneration:
description: |-
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format: int64
minimum: 0
type: integer
reason:
description: |-
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
type: string
status:
description: status of the condition, one of True, False, Unknown.
enum:
- "True"
- "False"
- Unknown
type: string
type:
description: |-
type of condition in CamelCase or in foo.example.com/CamelCase.
---
Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
useful (see .node.status.conditions), the ability to deconflict is important.
The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
type: array
type: object
type: object
served: true
storage: true
subresources:
status: {}
@@ -4,9 +4,9 @@ kind: CustomResourceDefinition
metadata: metadata:
annotations: annotations:
controller-gen.kubebuilder.io/version: v0.14.0 controller-gen.kubebuilder.io/version: v0.14.0
name: irsasetups.irsa.kkb0318.github.io name: irsasetups.irsa-manager.kkb0318.github.io
spec: spec:
group: irsa.kkb0318.github.io group: irsa-manager.kkb0318.github.io
names: names:
kind: IRSASetup kind: IRSASetup
listKind: IRSASetupList listKind: IRSASetupList
@@ -14,147 +14,153 @@ spec:
singular: irsasetup singular: irsasetup
scope: Namespaced scope: Namespaced
versions: versions:
- additionalPrinterColumns: - additionalPrinterColumns:
- jsonPath: .status.selfHostedSetup[?(@.type=="Ready")].status - jsonPath: .status.selfHostedSetup[?(@.type=="Ready")].status
name: SelfHostedReady name: SelfHostedReady
type: string type: string
name: v1alpha1 name: v1alpha1
schema: schema:
openAPIV3Schema: openAPIV3Schema:
description: IRSASetup represents a configuration for setting up IAM Roles description:
for Service Accounts (IRSA) in a Kubernetes cluster. IRSASetup represents a configuration for setting up IAM Roles
properties: for Service Accounts (IRSA) in a Kubernetes cluster.
apiVersion: properties:
description: |- apiVersion:
APIVersion defines the versioned schema of this representation of an object. description: |-
Servers should convert recognized schemas to the latest internal value, and APIVersion defines the versioned schema of this representation of an object.
may reject unrecognized values. Servers should convert recognized schemas to the latest internal value, and
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources may reject unrecognized values.
type: string More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind: type: string
description: |- kind:
Kind is a string value representing the REST resource this object represents. description: |-
Servers may infer this from the endpoint the client submits requests to. Kind is a string value representing the REST resource this object represents.
Cannot be updated. Servers may infer this from the endpoint the client submits requests to.
In CamelCase. Cannot be updated.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds In CamelCase.
type: string More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata: type: string
type: object metadata:
spec: type: object
description: IRSASetupSpec defines the desired state of IRSASetup spec:
properties: description: IRSASetupSpec defines the desired state of IRSASetup
cleanup: properties:
description: |- cleanup:
Cleanup, when enabled, allows the IRSASetup to perform garbage collection description: |-
of resources that are no longer needed or managed. Cleanup, when enabled, allows the IRSASetup to perform garbage collection
type: boolean of resources that are no longer needed or managed.
discovery: type: boolean
description: |- discovery:
Discovery configures the IdP Discovery process, essential for setting up IRSA by locating description: |-
the OIDC provider information. Discovery configures the IdP Discovery process, essential for setting up IRSA by locating
properties: the OIDC provider information.
s3: properties:
description: S3 specifies the AWS S3 bucket details where the s3:
OIDC provider's discovery information is hosted. description:
S3 specifies the AWS S3 bucket details where the
OIDC provider's discovery information is hosted.
properties:
bucketName:
description:
BucketName is the name of the S3 bucket that
hosts the OIDC discovery information.
type: string
region:
description:
Region denotes the AWS region where the S3 bucket
is located.
type: string
required:
- bucketName
- region
type: object
type: object
mode:
description:
Mode specifies the mode of operation. Can be either "selfhosted"
or "eks".
type: string
required:
- cleanup
- discovery
- mode
type: object
status:
description: IRSASetupStatus defines the observed state of IRSASetup
properties:
selfHostedSetup:
items:
description:
"Condition contains details for one aspect of the current
state of this API Resource.\n---\nThis struct is intended for
direct use as an array at the field path .status.conditions. For
example,\n\n\n\ttype FooStatus struct{\n\t // Represents the
observations of a foo's current state.\n\t // Known .status.conditions.type
are: \"Available\", \"Progressing\", and \"Degraded\"\n\t //
+patchMergeKey=type\n\t // +patchStrategy=merge\n\t // +listType=map\n\t
\ // +listMapKey=type\n\t Conditions []metav1.Condition `json:\"conditions,omitempty\"
patchStrategy:\"merge\" patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t
\ // other fields\n\t}"
properties: properties:
bucketName: lastTransitionTime:
description: BucketName is the name of the S3 bucket that description: |-
hosts the OIDC discovery information. lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string type: string
region: message:
description: Region denotes the AWS region where the S3 bucket description: |-
is located. message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength: 32768
type: string
observedGeneration:
description: |-
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format: int64
minimum: 0
type: integer
reason:
description: |-
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
type: string
status:
description: status of the condition, one of True, False, Unknown.
enum:
- "True"
- "False"
- Unknown
type: string
type:
description: |-
type of condition in CamelCase or in foo.example.com/CamelCase.
---
Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
useful (see .node.status.conditions), the ability to deconflict is important.
The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string type: string
required: required:
- bucketName - lastTransitionTime
- region - message
- reason
- status
- type
type: object type: object
type: object type: array
mode: type: object
description: Mode specifies the mode of operation. Can be either "selfhosted" type: object
or "eks". served: true
type: string storage: true
required: subresources:
- cleanup status: {}
- discovery
- mode
type: object
status:
description: IRSASetupStatus defines the observed state of IRSASetup
properties:
selfHostedSetup:
items:
description: "Condition contains details for one aspect of the current
state of this API Resource.\n---\nThis struct is intended for
direct use as an array at the field path .status.conditions. For
example,\n\n\n\ttype FooStatus struct{\n\t // Represents the
observations of a foo's current state.\n\t // Known .status.conditions.type
are: \"Available\", \"Progressing\", and \"Degraded\"\n\t //
+patchMergeKey=type\n\t // +patchStrategy=merge\n\t // +listType=map\n\t
\ // +listMapKey=type\n\t Conditions []metav1.Condition `json:\"conditions,omitempty\"
patchStrategy:\"merge\" patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t
\ // other fields\n\t}"
properties:
lastTransitionTime:
description: |-
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string
message:
description: |-
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength: 32768
type: string
observedGeneration:
description: |-
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format: int64
minimum: 0
type: integer
reason:
description: |-
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
type: string
status:
description: status of the condition, one of True, False, Unknown.
enum:
- "True"
- "False"
- Unknown
type: string
type:
description: |-
type of condition in CamelCase or in foo.example.com/CamelCase.
---
Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
useful (see .node.status.conditions), the ability to deconflict is important.
The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
type: array
type: object
type: object
served: true
storage: true
subresources:
status: {}
+2 -2
View File
@@ -2,8 +2,8 @@
# since it depends on service name and namespace that are out of this kustomize package. # since it depends on service name and namespace that are out of this kustomize package.
# It should be run by config/default # It should be run by config/default
resources: resources:
- bases/irsa.kkb0318.github.io_irsasetups.yaml - bases/irsa-manager.kkb0318.github.io_irsasetups.yaml
- bases/irsa.kkb0318.github.io_irsas.yaml - bases/irsa-manager.kkb0318.github.io_irsas.yaml
#+kubebuilder:scaffold:crdkustomizeresource #+kubebuilder:scaffold:crdkustomizeresource
patches: patches:
+18 -18
View File
@@ -11,21 +11,21 @@ metadata:
app.kubernetes.io/managed-by: kustomize app.kubernetes.io/managed-by: kustomize
name: irsa-editor-role name: irsa-editor-role
rules: rules:
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsas - irsas
verbs: verbs:
- create - create
- delete - delete
- get - get
- list - list
- patch - patch
- update - update
- watch - watch
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsas/status - irsas/status
verbs: verbs:
- get - get
+14 -14
View File
@@ -11,17 +11,17 @@ metadata:
app.kubernetes.io/managed-by: kustomize app.kubernetes.io/managed-by: kustomize
name: irsa-viewer-role name: irsa-viewer-role
rules: rules:
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsas - irsas
verbs: verbs:
- get - get
- list - list
- watch - watch
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsas/status - irsas/status
verbs: verbs:
- get - get
+18 -18
View File
@@ -11,21 +11,21 @@ metadata:
app.kubernetes.io/managed-by: kustomize app.kubernetes.io/managed-by: kustomize
name: irsasetup-editor-role name: irsasetup-editor-role
rules: rules:
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsasetups - irsasetups
verbs: verbs:
- create - create
- delete - delete
- get - get
- list - list
- patch - patch
- update - update
- watch - watch
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsasetups/status - irsasetups/status
verbs: verbs:
- get - get
+14 -14
View File
@@ -11,17 +11,17 @@ metadata:
app.kubernetes.io/managed-by: kustomize app.kubernetes.io/managed-by: kustomize
name: irsasetup-viewer-role name: irsasetup-viewer-role
rules: rules:
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsasetups - irsasetups
verbs: verbs:
- get - get
- list - list
- watch - watch
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsasetups/status - irsasetups/status
verbs: verbs:
- get - get
+6 -6
View File
@@ -77,7 +77,7 @@ rules:
- update - update
- watch - watch
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsas - irsas
verbs: verbs:
@@ -89,13 +89,13 @@ rules:
- update - update
- watch - watch
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsas/finalizers - irsas/finalizers
verbs: verbs:
- update - update
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsas/status - irsas/status
verbs: verbs:
@@ -103,7 +103,7 @@ rules:
- patch - patch
- update - update
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsasetups - irsasetups
verbs: verbs:
@@ -115,13 +115,13 @@ rules:
- update - update
- watch - watch
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsasetups/finalizers - irsasetups/finalizers
verbs: verbs:
- update - update
- apiGroups: - apiGroups:
- irsa.kkb0318.github.io - irsa-manager.kkb0318.github.io
resources: resources:
- irsasetups/status - irsasetups/status
verbs: verbs:
+1 -1
View File
@@ -1,4 +1,4 @@
apiVersion: irsa.kkb0318.github.io/v1alpha1 apiVersion: irsa-manager.kkb0318.github.io/v1alpha1
kind: IRSA kind: IRSA
metadata: metadata:
labels: labels:
+1 -1
View File
@@ -1,4 +1,4 @@
apiVersion: irsa.kkb0318.github.io/v1alpha1 apiVersion: irsa-manager.kkb0318.github.io/v1alpha1
kind: IRSASetup kind: IRSASetup
metadata: metadata:
labels: labels:
+4 -4
View File
@@ -1,10 +1,10 @@
# API Reference # API Reference
## Packages ## Packages
- [irsa.kkb0318.github.io/v1alpha1](#irsakkb0318githubiov1alpha1) - [irsa-manager.kkb0318.github.io/v1alpha1](#irsa-managerkkb0318githubiov1alpha1)
## irsa.kkb0318.github.io/v1alpha1 ## irsa-manager.kkb0318.github.io/v1alpha1
Package v1alpha1 contains API Schema definitions for the irsa v1alpha1 API group Package v1alpha1 contains API Schema definitions for the irsa v1alpha1 API group
@@ -43,7 +43,7 @@ IRSA is the Schema for the irsas API
| Field | Description | Default | Validation | | Field | Description | Default | Validation |
| --- | --- | --- | --- | | --- | --- | --- | --- |
| `apiVersion` _string_ | `irsa.kkb0318.github.io/v1alpha1` | | | | `apiVersion` _string_ | `irsa-manager.kkb0318.github.io/v1alpha1` | | |
| `kind` _string_ | `IRSA` | | | | `kind` _string_ | `IRSA` | | |
| `metadata` _[ObjectMeta](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#objectmeta-v1-meta)_ | Refer to Kubernetes API documentation for fields of `metadata`. | | | | `metadata` _[ObjectMeta](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#objectmeta-v1-meta)_ | Refer to Kubernetes API documentation for fields of `metadata`. | | |
| `spec` _[IRSASpec](#irsaspec)_ | | | | | `spec` _[IRSASpec](#irsaspec)_ | | | |
@@ -80,7 +80,7 @@ IRSASetup represents a configuration for setting up IAM Roles for Service Accoun
| Field | Description | Default | Validation | | Field | Description | Default | Validation |
| --- | --- | --- | --- | | --- | --- | --- | --- |
| `apiVersion` _string_ | `irsa.kkb0318.github.io/v1alpha1` | | | | `apiVersion` _string_ | `irsa-manager.kkb0318.github.io/v1alpha1` | | |
| `kind` _string_ | `IRSASetup` | | | | `kind` _string_ | `IRSASetup` | | |
| `metadata` _[ObjectMeta](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#objectmeta-v1-meta)_ | Refer to Kubernetes API documentation for fields of `metadata`. | | | | `metadata` _[ObjectMeta](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#objectmeta-v1-meta)_ | Refer to Kubernetes API documentation for fields of `metadata`. | | |
| `spec` _[IRSASetupSpec](#irsasetupspec)_ | | | | | `spec` _[IRSASetupSpec](#irsasetupspec)_ | | | |
+1 -1
View File
@@ -1,4 +1,4 @@
apiVersion: irsa.kkb0318.github.io/v1alpha1 apiVersion: irsa-manager.kkb0318.github.io/v1alpha1
kind: IRSA kind: IRSA
metadata: metadata:
name: irsa-sample name: irsa-sample
+1 -1
View File
@@ -1,4 +1,4 @@
apiVersion: irsa.kkb0318.github.io/v1alpha1 apiVersion: irsa-manager.kkb0318.github.io/v1alpha1
kind: IRSASetup kind: IRSASetup
metadata: metadata:
name: irsa-init name: irsa-init
+4 -4
View File
@@ -42,10 +42,10 @@ type IRSAReconciler struct {
AwsClient awsclient.AwsClient AwsClient awsclient.AwsClient
} }
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsas,verbs=get;list;watch;create;update;patch;delete //+kubebuilder:rbac:groups=irsa-manager.kkb0318.github.io,resources=irsas,verbs=get;list;watch;create;update;patch;delete
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsas/status,verbs=get;update;patch //+kubebuilder:rbac:groups=irsa-manager.kkb0318.github.io,resources=irsas/status,verbs=get;update;patch
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsas/finalizers,verbs=update //+kubebuilder:rbac:groups=irsa-manager.kkb0318.github.io,resources=irsas/finalizers,verbs=update
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsasetups,verbs=get;list //+kubebuilder:rbac:groups=irsa-manager.kkb0318.github.io,resources=irsasetups,verbs=get;list
//+kubebuilder:rbac:groups="",resources=serviceaccounts,verbs=get;list;watch;create;update;patch;delete //+kubebuilder:rbac:groups="",resources=serviceaccounts,verbs=get;list;watch;create;update;patch;delete
// Reconcile is part of the main kubernetes reconciliation loop which aims to // Reconcile is part of the main kubernetes reconciliation loop which aims to
+4 -4
View File
@@ -36,7 +36,7 @@ import (
"github.com/kkb0318/irsa-manager/internal/selfhosted/webhook" "github.com/kkb0318/irsa-manager/internal/selfhosted/webhook"
) )
const irsamanagerFinalizer = "irsa.kkb0318.github.io/finalizers" const irsamanagerFinalizer = "irsa-manager.kkb0318.github.io/finalizers"
// IRSASetupReconciler reconciles a IRSASetup object // IRSASetupReconciler reconciles a IRSASetup object
type IRSASetupReconciler struct { type IRSASetupReconciler struct {
@@ -45,9 +45,9 @@ type IRSASetupReconciler struct {
AwsClient awsclient.AwsClient AwsClient awsclient.AwsClient
} }
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsasetups,verbs=get;list;watch;create;update;patch;delete //+kubebuilder:rbac:groups=irsa-manager.kkb0318.github.io,resources=irsasetups,verbs=get;list;watch;create;update;patch;delete
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsasetups/status,verbs=get;update;patch //+kubebuilder:rbac:groups=irsa-manager.kkb0318.github.io,resources=irsasetups/status,verbs=get;update;patch
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsasetups/finalizers,verbs=update //+kubebuilder:rbac:groups=irsa-manager.kkb0318.github.io,resources=irsasetups/finalizers,verbs=update
//+kubebuilder:rbac:groups="",resources=secrets,verbs=get;list;watch;create;update;patch;delete //+kubebuilder:rbac:groups="",resources=secrets,verbs=get;list;watch;create;update;patch;delete
//+kubebuilder:rbac:groups="",resources=services,verbs=get;list;watch;create;update;patch;delete //+kubebuilder:rbac:groups="",resources=services,verbs=get;list;watch;create;update;patch;delete
//+kubebuilder:rbac:groups="",resources=serviceaccounts,verbs=get;list;watch;create;update;patch;delete //+kubebuilder:rbac:groups="",resources=serviceaccounts,verbs=get;list;watch;create;update;patch;delete