mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
add role, webhook resource
This commit is contained in:
@@ -32,6 +32,7 @@ import (
|
||||
"github.com/kkb0318/irsa-manager/internal/manifests"
|
||||
"github.com/kkb0318/irsa-manager/internal/selfhosted"
|
||||
"github.com/kkb0318/irsa-manager/internal/selfhosted/oidc"
|
||||
"github.com/kkb0318/irsa-manager/internal/selfhosted/webhook"
|
||||
)
|
||||
|
||||
const irsamanagerFinalizer = "irsa.kkb0318.github.io/finalizers"
|
||||
@@ -47,6 +48,11 @@ type IRSASetupReconciler struct {
|
||||
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsasetups/status,verbs=get;update;patch
|
||||
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsasetups/finalizers,verbs=update
|
||||
//+kubebuilder:rbac:groups="",resources=secrets,verbs=get;list;watch;create;update;patch;delete
|
||||
//+kubebuilder:rbac:groups="",resources=serviceaccounts,verbs=get;list;watch;create;update;patch;delete
|
||||
//+kubebuilder:rbac:groups="apps",resources=deployments,verbs=get;list;watch;create;update;patch;delete
|
||||
//+kubebuilder:rbac:groups="rbac.authorization.k8s.io",resources=clusterroles,verbs=get;list;watch;create;update;patch;delete
|
||||
//+kubebuilder:rbac:groups="rbac.authorization.k8s.io",resources=clusterrolebindings,verbs=get;list;watch;create;update;patch;delete
|
||||
//+kubebuilder:rbac:groups="admissionregistration.k8s.io",resources=mutatingwebhookconfigurations,verbs=get;list;watch;create;update;patch;delete
|
||||
|
||||
// Reconcile is part of the main kubernetes reconciliation loop which aims to
|
||||
// move the current state of the cluster closer to the desired state.
|
||||
@@ -170,6 +176,15 @@ func reconcileSelfhosted(ctx context.Context, obj *irsav1alpha1.IRSASetup, awsCl
|
||||
kubeHandler := handler.NewKubernetesHandler(kubeClient)
|
||||
kubeHandler.Append(secret)
|
||||
|
||||
// for webhook setup
|
||||
webhookSetup, err := webhook.NewWebHookSetup()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
for _, r := range webhookSetup.Resources() {
|
||||
kubeHandler.Append(r)
|
||||
}
|
||||
|
||||
var e error
|
||||
var reason irsav1alpha1.SelfHostedReason
|
||||
defer func() {
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
package selfhosted
|
||||
|
||||
import "context"
|
||||
import (
|
||||
"context"
|
||||
)
|
||||
|
||||
func Execute(ctx context.Context, idpComponentsFactory OIDCIdPFactory, forceUpdate bool) error {
|
||||
issuerMeta := idpComponentsFactory.IssuerMeta()
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
package webhook
|
||||
|
||||
import (
|
||||
"k8s.io/api/admissionregistration/v1beta1"
|
||||
regv1 "k8s.io/api/admissionregistration/v1"
|
||||
appsv1 "k8s.io/api/apps/v1"
|
||||
corev1 "k8s.io/api/core/v1"
|
||||
rbacv1 "k8s.io/api/rbac/v1"
|
||||
@@ -46,39 +46,42 @@ func newBaseManifestFactory() *baseManifestFactory {
|
||||
}
|
||||
}
|
||||
|
||||
func (b *baseManifestFactory) mutatingWebhookConfiguration() *v1beta1.MutatingWebhookConfiguration {
|
||||
func (b *baseManifestFactory) mutatingWebhookConfiguration() *regv1.MutatingWebhookConfiguration {
|
||||
path := "/mutate"
|
||||
failurePolicy := v1beta1.Ignore
|
||||
return &v1beta1.MutatingWebhookConfiguration{
|
||||
failurePolicy := regv1.Ignore
|
||||
sideEffects := regv1.SideEffectClassNone
|
||||
return ®v1.MutatingWebhookConfiguration{
|
||||
TypeMeta: metav1.TypeMeta{
|
||||
APIVersion: v1beta1.SchemeGroupVersion.String(),
|
||||
APIVersion: regv1.SchemeGroupVersion.String(),
|
||||
Kind: "MutatingWebhookConfiguration",
|
||||
},
|
||||
ObjectMeta: metav1.ObjectMeta{
|
||||
Name: b.mutatingWebhookConfigurationMeta.Name,
|
||||
Namespace: b.mutatingWebhookConfigurationMeta.Namespace,
|
||||
},
|
||||
Webhooks: []v1beta1.MutatingWebhook{
|
||||
Webhooks: []regv1.MutatingWebhook{
|
||||
{
|
||||
Name: "pod-identity-webhook.amazonaws.com",
|
||||
ClientConfig: v1beta1.WebhookClientConfig{
|
||||
Service: &v1beta1.ServiceReference{
|
||||
ClientConfig: regv1.WebhookClientConfig{
|
||||
Service: ®v1.ServiceReference{
|
||||
Name: b.serviceMeta.Name,
|
||||
Namespace: b.serviceMeta.Namespace,
|
||||
Path: &path,
|
||||
},
|
||||
},
|
||||
Rules: []v1beta1.RuleWithOperations{
|
||||
Rules: []regv1.RuleWithOperations{
|
||||
{
|
||||
Operations: []v1beta1.OperationType{"CREATE"},
|
||||
Rule: v1beta1.Rule{
|
||||
Operations: []regv1.OperationType{"CREATE"},
|
||||
Rule: regv1.Rule{
|
||||
APIGroups: []string{""},
|
||||
APIVersions: []string{"v1"},
|
||||
Resources: []string{"pods"},
|
||||
},
|
||||
},
|
||||
},
|
||||
FailurePolicy: &failurePolicy,
|
||||
FailurePolicy: &failurePolicy,
|
||||
SideEffects: &sideEffects,
|
||||
AdmissionReviewVersions: []string{"v1beta1"},
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
@@ -6,7 +6,7 @@ import (
|
||||
|
||||
"github.com/goccy/go-yaml"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"k8s.io/api/admissionregistration/v1beta1"
|
||||
regv1 "k8s.io/api/admissionregistration/v1"
|
||||
appsv1 "k8s.io/api/apps/v1"
|
||||
corev1 "k8s.io/api/core/v1"
|
||||
rbacv1 "k8s.io/api/rbac/v1"
|
||||
@@ -84,7 +84,7 @@ func TestBaseManifests(t *testing.T) {
|
||||
}
|
||||
|
||||
func testMutatingWebhookConfiguration() client.Object {
|
||||
return &v1beta1.MutatingWebhookConfiguration{}
|
||||
return ®v1.MutatingWebhookConfiguration{}
|
||||
}
|
||||
|
||||
func testService() client.Object {
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
apiVersion: admissionregistration.k8s.io/v1beta1
|
||||
apiVersion: admissionregistration.k8s.io/v1
|
||||
kind: MutatingWebhookConfiguration
|
||||
metadata:
|
||||
name: pod-identity-webhook
|
||||
@@ -16,3 +16,5 @@ webhooks:
|
||||
apiGroups: [""]
|
||||
apiVersions: ["v1"]
|
||||
resources: ["pods"]
|
||||
sideEffects: None
|
||||
admissionReviewVersions: ["v1beta1"]
|
||||
|
||||
@@ -8,7 +8,7 @@ import (
|
||||
"sigs.k8s.io/controller-runtime/pkg/client"
|
||||
)
|
||||
|
||||
type AwsWebhook struct {
|
||||
type WebhookSetup struct {
|
||||
resources []client.Object
|
||||
}
|
||||
|
||||
@@ -19,13 +19,17 @@ func secretNamespacedName() types.NamespacedName {
|
||||
}
|
||||
}
|
||||
|
||||
func NewWebHook() (*AwsWebhook, error) {
|
||||
func (w *WebhookSetup) Resources() []client.Object {
|
||||
return w.resources
|
||||
}
|
||||
|
||||
func NewWebHookSetup() (*WebhookSetup, error) {
|
||||
factory := newBaseManifestFactory()
|
||||
resources, err := myCertificate(factory)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return &AwsWebhook{resources}, nil
|
||||
return &WebhookSetup{resources}, nil
|
||||
}
|
||||
|
||||
func myCertificate(base *baseManifestFactory) ([]client.Object, error) {
|
||||
|
||||
Reference in New Issue
Block a user