mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
bugfix irsa truct policy setting
This commit is contained in:
@@ -134,6 +134,7 @@ _Appears in:_
|
|||||||
|
|
||||||
| Field | Description | Default | Validation |
|
| Field | Description | Default | Validation |
|
||||||
| --- | --- | --- | --- |
|
| --- | --- | --- | --- |
|
||||||
|
| `cleanup` _boolean_ | Cleanup, when enabled, allows the IRSA to perform garbage collection<br />of resources that are no longer needed or managed. | | |
|
||||||
| `serviceAccount` _[IRSAServiceAccount](#irsaserviceaccount)_ | ServiceAccount represents the Kubernetes service account associated with the IRSA | | |
|
| `serviceAccount` _[IRSAServiceAccount](#irsaserviceaccount)_ | ServiceAccount represents the Kubernetes service account associated with the IRSA | | |
|
||||||
| `iamRole` _[IamRole](#iamrole)_ | IamRole represents the IAM role details associated with the IRSA | | |
|
| `iamRole` _[IamRole](#iamrole)_ | IamRole represents the IAM role details associated with the IRSA | | |
|
||||||
| `iamPolicies` _string array_ | IamPolicies represents the list of IAM policies to be attached to the IAM role | | |
|
| `iamPolicies` _string array_ | IamPolicies represents the list of IAM policies to be attached to the IAM role | | |
|
||||||
|
|||||||
@@ -45,6 +45,8 @@ type IRSAReconciler struct {
|
|||||||
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsas,verbs=get;list;watch;create;update;patch;delete
|
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsas,verbs=get;list;watch;create;update;patch;delete
|
||||||
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsas/status,verbs=get;update;patch
|
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsas/status,verbs=get;update;patch
|
||||||
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsas/finalizers,verbs=update
|
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsas/finalizers,verbs=update
|
||||||
|
//+kubebuilder:rbac:groups=irsa.kkb0318.github.io,resources=irsasetups,verbs=get;list
|
||||||
|
//+kubebuilder:rbac:groups="",resources=serviceaccounts,verbs=get;list;watch;create;update;patch;delete
|
||||||
|
|
||||||
// Reconcile is part of the main kubernetes reconciliation loop which aims to
|
// Reconcile is part of the main kubernetes reconciliation loop which aims to
|
||||||
// move the current state of the cluster closer to the desired state.
|
// move the current state of the cluster closer to the desired state.
|
||||||
@@ -108,7 +110,6 @@ func (r *IRSAReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ctrl.
|
|||||||
return ctrl.Result{}, err
|
return ctrl.Result{}, err
|
||||||
}
|
}
|
||||||
|
|
||||||
// roleArn: arn:aws:iam::{accountId}:role/{roleName}
|
|
||||||
log.Info("successfully reconciled")
|
log.Info("successfully reconciled")
|
||||||
return ctrl.Result{}, nil
|
return ctrl.Result{}, nil
|
||||||
}
|
}
|
||||||
@@ -135,7 +136,7 @@ func (r *IRSAReconciler) reconcileDelete(ctx context.Context, obj *irsav1alpha1.
|
|||||||
}
|
}
|
||||||
|
|
||||||
func (r *IRSAReconciler) reconcile(ctx context.Context, obj *irsav1alpha1.IRSA, kubeClient *kubernetes.KubernetesClient) error {
|
func (r *IRSAReconciler) reconcile(ctx context.Context, obj *irsav1alpha1.IRSA, kubeClient *kubernetes.KubernetesClient) error {
|
||||||
list, err := kubeClient.List(ctx, irsav1alpha1.GroupVersion.WithKind(irsav1alpha1.IRSAKind))
|
list, err := kubeClient.List(ctx, irsav1alpha1.GroupVersion.WithKind(irsav1alpha1.IRSASetupKind))
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -159,8 +160,12 @@ func (r *IRSAReconciler) reconcile(ctx context.Context, obj *irsav1alpha1.IRSA,
|
|||||||
Policies: obj.Spec.IamPolicies,
|
Policies: obj.Spec.IamPolicies,
|
||||||
AccountId: accountId,
|
AccountId: accountId,
|
||||||
}
|
}
|
||||||
|
issuerMeta, err := issuer.NewS3IssuerMeta(&irsaSetup.Spec.Discovery.S3)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
err = r.AwsClient.IamClient().CreateIRSARole(ctx,
|
err = r.AwsClient.IamClient().CreateIRSARole(ctx,
|
||||||
issuer.NewS3IssuerMeta(irsaSetup.Spec.Discovery.S3),
|
issuerMeta,
|
||||||
roleManager,
|
roleManager,
|
||||||
)
|
)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|||||||
@@ -154,10 +154,14 @@ func (r *IRSASetupReconciler) reconcileDelete(ctx context.Context, obj *irsav1al
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
issuerMeta, err := issuer.NewS3IssuerMeta(&obj.Spec.Discovery.S3)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
return selfhosted.Delete(
|
return selfhosted.Delete(
|
||||||
ctx,
|
ctx,
|
||||||
factory,
|
factory,
|
||||||
issuer.NewS3IssuerMeta(obj.Spec.Discovery.S3),
|
issuerMeta,
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -212,10 +216,14 @@ func reconcileSelfhosted(ctx context.Context, obj *irsav1alpha1.IRSASetup, awsCl
|
|||||||
string(irsav1alpha1.SelfHostedReasonFailedKeys),
|
string(irsav1alpha1.SelfHostedReasonFailedKeys),
|
||||||
string(irsav1alpha1.SelfHostedReasonFailedOidc),
|
string(irsav1alpha1.SelfHostedReasonFailedOidc),
|
||||||
)
|
)
|
||||||
|
issuerMeta, err := issuer.NewS3IssuerMeta(&obj.Spec.Discovery.S3)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
err = selfhosted.Execute(
|
err = selfhosted.Execute(
|
||||||
ctx,
|
ctx,
|
||||||
factory,
|
factory,
|
||||||
issuer.NewS3IssuerMeta(obj.Spec.Discovery.S3),
|
issuerMeta,
|
||||||
forceUpdate,
|
forceUpdate,
|
||||||
)
|
)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|||||||
@@ -16,8 +16,13 @@ type S3IssuerMeta struct {
|
|||||||
bucketName string
|
bucketName string
|
||||||
}
|
}
|
||||||
|
|
||||||
func NewS3IssuerMeta(s3 irsav1alpha1.S3Discovery) *S3IssuerMeta {
|
func NewS3IssuerMeta(s3 *irsav1alpha1.S3Discovery) (*S3IssuerMeta, error) {
|
||||||
return &S3IssuerMeta{s3.Region, s3.BucketName}
|
region := s3.Region
|
||||||
|
bucketName := s3.BucketName
|
||||||
|
if region == "" || bucketName == "" {
|
||||||
|
return nil, fmt.Errorf("s3 region and bucket name must not be empty. region: %s, bucketName: %s", region, bucketName)
|
||||||
|
}
|
||||||
|
return &S3IssuerMeta{region, bucketName}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func (i *S3IssuerMeta) IssuerHostPath() string {
|
func (i *S3IssuerMeta) IssuerHostPath() string {
|
||||||
|
|||||||
Reference in New Issue
Block a user