diff --git a/docs/api.md b/docs/api.md index b70f842..2d8ae5f 100644 --- a/docs/api.md +++ b/docs/api.md @@ -134,6 +134,7 @@ _Appears in:_ | Field | Description | Default | Validation | | --- | --- | --- | --- | +| `cleanup` _boolean_ | Cleanup, when enabled, allows the IRSA to perform garbage collection
of resources that are no longer needed or managed. | | | | `serviceAccount` _[IRSAServiceAccount](#irsaserviceaccount)_ | ServiceAccount represents the Kubernetes service account associated with the IRSA | | | | `iamRole` _[IamRole](#iamrole)_ | IamRole represents the IAM role details associated with the IRSA | | | | `iamPolicies` _string array_ | IamPolicies represents the list of IAM policies to be attached to the IAM role | | | diff --git a/internal/controller/irsa_controller.go b/internal/controller/irsa_controller.go index b078b21..6f6497f 100644 --- a/internal/controller/irsa_controller.go +++ b/internal/controller/irsa_controller.go @@ -45,6 +45,8 @@ type IRSAReconciler struct { //+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsas,verbs=get;list;watch;create;update;patch;delete //+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsas/status,verbs=get;update;patch //+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsas/finalizers,verbs=update +//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsasetups,verbs=get;list +//+kubebuilder:rbac:groups="",resources=serviceaccounts,verbs=get;list;watch;create;update;patch;delete // Reconcile is part of the main kubernetes reconciliation loop which aims to // move the current state of the cluster closer to the desired state. @@ -108,7 +110,6 @@ func (r *IRSAReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ctrl. return ctrl.Result{}, err } - // roleArn: arn:aws:iam::{accountId}:role/{roleName} log.Info("successfully reconciled") return ctrl.Result{}, nil } @@ -135,7 +136,7 @@ func (r *IRSAReconciler) reconcileDelete(ctx context.Context, obj *irsav1alpha1. } func (r *IRSAReconciler) reconcile(ctx context.Context, obj *irsav1alpha1.IRSA, kubeClient *kubernetes.KubernetesClient) error { - list, err := kubeClient.List(ctx, irsav1alpha1.GroupVersion.WithKind(irsav1alpha1.IRSAKind)) + list, err := kubeClient.List(ctx, irsav1alpha1.GroupVersion.WithKind(irsav1alpha1.IRSASetupKind)) if err != nil { return err } @@ -159,8 +160,12 @@ func (r *IRSAReconciler) reconcile(ctx context.Context, obj *irsav1alpha1.IRSA, Policies: obj.Spec.IamPolicies, AccountId: accountId, } + issuerMeta, err := issuer.NewS3IssuerMeta(&irsaSetup.Spec.Discovery.S3) + if err != nil { + return err + } err = r.AwsClient.IamClient().CreateIRSARole(ctx, - issuer.NewS3IssuerMeta(irsaSetup.Spec.Discovery.S3), + issuerMeta, roleManager, ) if err != nil { diff --git a/internal/controller/irsasetup_controller.go b/internal/controller/irsasetup_controller.go index 84baffc..ad17d72 100644 --- a/internal/controller/irsasetup_controller.go +++ b/internal/controller/irsasetup_controller.go @@ -154,10 +154,14 @@ func (r *IRSASetupReconciler) reconcileDelete(ctx context.Context, obj *irsav1al if err != nil { return err } + issuerMeta, err := issuer.NewS3IssuerMeta(&obj.Spec.Discovery.S3) + if err != nil { + return err + } return selfhosted.Delete( ctx, factory, - issuer.NewS3IssuerMeta(obj.Spec.Discovery.S3), + issuerMeta, ) } @@ -212,10 +216,14 @@ func reconcileSelfhosted(ctx context.Context, obj *irsav1alpha1.IRSASetup, awsCl string(irsav1alpha1.SelfHostedReasonFailedKeys), string(irsav1alpha1.SelfHostedReasonFailedOidc), ) + issuerMeta, err := issuer.NewS3IssuerMeta(&obj.Spec.Discovery.S3) + if err != nil { + return err + } err = selfhosted.Execute( ctx, factory, - issuer.NewS3IssuerMeta(obj.Spec.Discovery.S3), + issuerMeta, forceUpdate, ) if err != nil { diff --git a/internal/issuer/issuer.go b/internal/issuer/issuer.go index 42bd5f0..7329702 100644 --- a/internal/issuer/issuer.go +++ b/internal/issuer/issuer.go @@ -16,8 +16,13 @@ type S3IssuerMeta struct { bucketName string } -func NewS3IssuerMeta(s3 irsav1alpha1.S3Discovery) *S3IssuerMeta { - return &S3IssuerMeta{s3.Region, s3.BucketName} +func NewS3IssuerMeta(s3 *irsav1alpha1.S3Discovery) (*S3IssuerMeta, error) { + region := s3.Region + bucketName := s3.BucketName + if region == "" || bucketName == "" { + return nil, fmt.Errorf("s3 region and bucket name must not be empty. region: %s, bucketName: %s", region, bucketName) + } + return &S3IssuerMeta{region, bucketName}, nil } func (i *S3IssuerMeta) IssuerHostPath() string {