change issuer settings of irsa_controller for eks mode

This commit is contained in:
kkb0318
2024-07-26 20:29:02 +09:00
parent 5ffb448ecd
commit 9d7542b7ad
4 changed files with 112 additions and 19 deletions
+1 -8
View File
@@ -51,13 +51,6 @@ type IRSAReconciler struct {
// Reconcile is part of the main kubernetes reconciliation loop which aims to // Reconcile is part of the main kubernetes reconciliation loop which aims to
// move the current state of the cluster closer to the desired state. // move the current state of the cluster closer to the desired state.
// TODO(user): Modify the Reconcile function to compare the state specified by
// the IRSA object against the actual cluster state, and then
// perform operations to make the cluster state reflect the state specified by
// the user.
//
// For more details, check Reconcile and its Result here:
// - https://pkg.go.dev/sigs.k8s.io/controller-runtime@v0.16.3/pkg/reconcile
func (r *IRSAReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ctrl.Result, error) { func (r *IRSAReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ctrl.Result, error) {
log := ctrllog.FromContext(ctx) log := ctrllog.FromContext(ctx)
obj := &irsav1alpha1.IRSA{} obj := &irsav1alpha1.IRSA{}
@@ -152,7 +145,7 @@ func (r *IRSAReconciler) reconcile(ctx context.Context, obj *irsav1alpha1.IRSA,
return fmt.Errorf("error converting to IRSASetup for %s: %v", list.Items[0].GetName(), err) return fmt.Errorf("error converting to IRSASetup for %s: %v", list.Items[0].GetName(), err)
} }
serviceAccount := obj.Spec.ServiceAccount serviceAccount := obj.Spec.ServiceAccount
issuerMeta, err := issuer.NewS3IssuerMeta(&irsaSetup.Spec.Discovery.S3) issuerMeta, err := issuer.NewOIDCIssuerMeta(irsaSetup)
if err != nil { if err != nil {
return err return err
} }
+84 -2
View File
@@ -211,7 +211,7 @@ var _ = Describe("IRSA Controller", func() {
f: newServiceAccount, f: newServiceAccount,
}, },
) )
f := createCallBack(ctx, r, typeNamespacedName, obj) f := createCallBackForFixingNamespace(ctx, r, typeNamespacedName, obj)
By("Add Namespace 'default'") By("Add Namespace 'default'")
f(obj.Spec.ServiceAccount.Name, []string{"default", "kube-system"}) f(obj.Spec.ServiceAccount.Name, []string{"default", "kube-system"})
@@ -222,6 +222,75 @@ var _ = Describe("IRSA Controller", func() {
f: newServiceAccount, f: newServiceAccount,
}) })
By("removing the custom resource for the Kind")
Eventually(func() error {
return k8sClient.Delete(ctx, obj)
}, timeout).Should(Succeed())
_, err = r.Reconcile(ctx, reconcile.Request{
NamespacedName: typeNamespacedName,
})
Expect(err).To(Not(HaveOccurred()))
for _, expect := range expected {
checkNoExist(expect)
}
},
},
{
name: "should update serviceaccount successfully with EKS mode",
obj: &irsav1alpha1.IRSA{
ObjectMeta: metav1.ObjectMeta{
Name: "test-resource-eks-1",
Namespace: "default",
},
Spec: irsav1alpha1.IRSASpec{
Cleanup: true,
ServiceAccount: irsav1alpha1.IRSAServiceAccount{
Name: "sa-eks-1",
Namespaces: []string{
"kube-system",
},
},
},
},
irsaSetupObj: newMockIRSASetupForEKS(),
f: func(r *IRSAReconciler, obj *irsav1alpha1.IRSA) {
expected := []expectedResource{
{
NamespacedName: types.NamespacedName{Name: "sa-eks-1", Namespace: "kube-system"},
f: newServiceAccount,
},
{
NamespacedName: types.NamespacedName{Name: "sa-eks-1", Namespace: "default"},
f: newServiceAccount,
},
}
By("Reconciling the created resource")
typeNamespacedName := types.NamespacedName{
Name: obj.Name,
Namespace: obj.Namespace,
}
_, err := r.Reconcile(ctx, reconcile.Request{
NamespacedName: typeNamespacedName,
})
Expect(err).NotTo(HaveOccurred())
checkExist(
expectedResource{
NamespacedName: types.NamespacedName{Name: "sa-eks-1", Namespace: "kube-system"},
f: newServiceAccount,
},
)
f := createCallBackForFixingNamespace(ctx, r, typeNamespacedName, obj)
By("Add Namespace 'default'")
f(obj.Spec.ServiceAccount.Name, []string{"default", "kube-system"})
By("Remove Namespace 'kube-system'")
f(obj.Spec.ServiceAccount.Name, []string{"default"})
checkNoExist(expectedResource{
NamespacedName: types.NamespacedName{Name: "sa-eks-1", Namespace: "kube-system"},
f: newServiceAccount,
})
By("removing the custom resource for the Kind") By("removing the custom resource for the Kind")
Eventually(func() error { Eventually(func() error {
return k8sClient.Delete(ctx, obj) return k8sClient.Delete(ctx, obj)
@@ -298,7 +367,20 @@ func newMockIRSASetup() *irsav1alpha1.IRSASetup {
} }
} }
func createCallBack(ctx context.Context, r *IRSAReconciler, typeNamespacedName types.NamespacedName, obj *irsav1alpha1.IRSA) func(name string, namespaces []string) { func newMockIRSASetupForEKS() *irsav1alpha1.IRSASetup {
return &irsav1alpha1.IRSASetup{
ObjectMeta: metav1.ObjectMeta{
Name: "test",
Namespace: "default",
},
Spec: irsav1alpha1.IRSASetupSpec{
Mode: irsav1alpha1.ModeEks,
IamOIDCProvider: "oidc.example",
},
}
}
func createCallBackForFixingNamespace(ctx context.Context, r *IRSAReconciler, typeNamespacedName types.NamespacedName, obj *irsav1alpha1.IRSA) func(name string, namespaces []string) {
return func(name string, namespaces []string) { return func(name string, namespaces []string) {
fixNamespacesAndReconcile(ctx, r, typeNamespacedName, obj, name, namespaces) fixNamespacesAndReconcile(ctx, r, typeNamespacedName, obj, name, namespaces)
} }
@@ -59,13 +59,6 @@ type IRSASetupReconciler struct {
// Reconcile is part of the main kubernetes reconciliation loop which aims to // Reconcile is part of the main kubernetes reconciliation loop which aims to
// move the current state of the cluster closer to the desired state. // move the current state of the cluster closer to the desired state.
// TODO(user): Modify the Reconcile function to compare the state specified by
// the IRSASetup object against the actual cluster state, and then
// perform operations to make the cluster state reflect the state specified by
// the user.
//
// For more details, check Reconcile and its Result here:
// - https://pkg.go.dev/sigs.k8s.io/controller-runtime@v0.16.3/pkg/reconcile
func (r *IRSASetupReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ctrl.Result, error) { func (r *IRSASetupReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ctrl.Result, error) {
log := ctrllog.FromContext(ctx) log := ctrllog.FromContext(ctx)
obj := &irsav1alpha1.IRSASetup{} obj := &irsav1alpha1.IRSASetup{}
+27 -2
View File
@@ -16,6 +16,13 @@ type S3IssuerMeta struct {
bucketName string bucketName string
} }
func NewOIDCIssuerMeta(i *irsav1alpha1.IRSASetup) (OIDCIssuerMeta, error) {
if i.Spec.Mode == irsav1alpha1.ModeEks {
return newIamOIDCProviderIssuerMeta(i.Spec.IamOIDCProvider)
}
return NewS3IssuerMeta(&i.Spec.Discovery.S3)
}
func NewS3IssuerMeta(s3 *irsav1alpha1.S3Discovery) (*S3IssuerMeta, error) { func NewS3IssuerMeta(s3 *irsav1alpha1.S3Discovery) (*S3IssuerMeta, error) {
region := s3.Region region := s3.Region
bucketName := s3.BucketName bucketName := s3.BucketName
@@ -32,6 +39,24 @@ func (i *S3IssuerMeta) IssuerHostPath() string {
// IssuerUrl constructs the URL path for the OIDC issuer based on the provided AWS region and bucket name. // IssuerUrl constructs the URL path for the OIDC issuer based on the provided AWS region and bucket name.
// This utility function generates the expected host path for accessing the OIDC configuration stored in an S3 bucket. // This utility function generates the expected host path for accessing the OIDC configuration stored in an S3 bucket.
func (i *S3IssuerMeta) IssuerUrl() string { func (i *S3IssuerMeta) IssuerUrl() string {
return fmt.Sprintf("https://%s", i. return fmt.Sprintf("https://%s", i.IssuerHostPath())
IssuerHostPath()) }
func newIamOIDCProviderIssuerMeta(providerName string) (*iamOIDCProviderIssuerMeta, error) {
if providerName == "" {
return nil, fmt.Errorf("IAM OIDC Provider Name must not be empty")
}
return &iamOIDCProviderIssuerMeta{providerName}, nil
}
type iamOIDCProviderIssuerMeta struct {
providerName string
}
func (i *iamOIDCProviderIssuerMeta) IssuerHostPath() string {
return i.providerName
}
func (i *iamOIDCProviderIssuerMeta) IssuerUrl() string {
return fmt.Sprintf("https://%s", i.IssuerHostPath())
} }