mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
change issuer settings of irsa_controller for eks mode
This commit is contained in:
@@ -51,13 +51,6 @@ type IRSAReconciler struct {
|
|||||||
|
|
||||||
// Reconcile is part of the main kubernetes reconciliation loop which aims to
|
// Reconcile is part of the main kubernetes reconciliation loop which aims to
|
||||||
// move the current state of the cluster closer to the desired state.
|
// move the current state of the cluster closer to the desired state.
|
||||||
// TODO(user): Modify the Reconcile function to compare the state specified by
|
|
||||||
// the IRSA object against the actual cluster state, and then
|
|
||||||
// perform operations to make the cluster state reflect the state specified by
|
|
||||||
// the user.
|
|
||||||
//
|
|
||||||
// For more details, check Reconcile and its Result here:
|
|
||||||
// - https://pkg.go.dev/sigs.k8s.io/controller-runtime@v0.16.3/pkg/reconcile
|
|
||||||
func (r *IRSAReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ctrl.Result, error) {
|
func (r *IRSAReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ctrl.Result, error) {
|
||||||
log := ctrllog.FromContext(ctx)
|
log := ctrllog.FromContext(ctx)
|
||||||
obj := &irsav1alpha1.IRSA{}
|
obj := &irsav1alpha1.IRSA{}
|
||||||
@@ -152,7 +145,7 @@ func (r *IRSAReconciler) reconcile(ctx context.Context, obj *irsav1alpha1.IRSA,
|
|||||||
return fmt.Errorf("error converting to IRSASetup for %s: %v", list.Items[0].GetName(), err)
|
return fmt.Errorf("error converting to IRSASetup for %s: %v", list.Items[0].GetName(), err)
|
||||||
}
|
}
|
||||||
serviceAccount := obj.Spec.ServiceAccount
|
serviceAccount := obj.Spec.ServiceAccount
|
||||||
issuerMeta, err := issuer.NewS3IssuerMeta(&irsaSetup.Spec.Discovery.S3)
|
issuerMeta, err := issuer.NewOIDCIssuerMeta(irsaSetup)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -211,7 +211,7 @@ var _ = Describe("IRSA Controller", func() {
|
|||||||
f: newServiceAccount,
|
f: newServiceAccount,
|
||||||
},
|
},
|
||||||
)
|
)
|
||||||
f := createCallBack(ctx, r, typeNamespacedName, obj)
|
f := createCallBackForFixingNamespace(ctx, r, typeNamespacedName, obj)
|
||||||
|
|
||||||
By("Add Namespace 'default'")
|
By("Add Namespace 'default'")
|
||||||
f(obj.Spec.ServiceAccount.Name, []string{"default", "kube-system"})
|
f(obj.Spec.ServiceAccount.Name, []string{"default", "kube-system"})
|
||||||
@@ -222,6 +222,75 @@ var _ = Describe("IRSA Controller", func() {
|
|||||||
f: newServiceAccount,
|
f: newServiceAccount,
|
||||||
})
|
})
|
||||||
|
|
||||||
|
By("removing the custom resource for the Kind")
|
||||||
|
Eventually(func() error {
|
||||||
|
return k8sClient.Delete(ctx, obj)
|
||||||
|
}, timeout).Should(Succeed())
|
||||||
|
_, err = r.Reconcile(ctx, reconcile.Request{
|
||||||
|
NamespacedName: typeNamespacedName,
|
||||||
|
})
|
||||||
|
Expect(err).To(Not(HaveOccurred()))
|
||||||
|
for _, expect := range expected {
|
||||||
|
checkNoExist(expect)
|
||||||
|
}
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "should update serviceaccount successfully with EKS mode",
|
||||||
|
obj: &irsav1alpha1.IRSA{
|
||||||
|
ObjectMeta: metav1.ObjectMeta{
|
||||||
|
Name: "test-resource-eks-1",
|
||||||
|
Namespace: "default",
|
||||||
|
},
|
||||||
|
Spec: irsav1alpha1.IRSASpec{
|
||||||
|
Cleanup: true,
|
||||||
|
ServiceAccount: irsav1alpha1.IRSAServiceAccount{
|
||||||
|
Name: "sa-eks-1",
|
||||||
|
Namespaces: []string{
|
||||||
|
"kube-system",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
irsaSetupObj: newMockIRSASetupForEKS(),
|
||||||
|
f: func(r *IRSAReconciler, obj *irsav1alpha1.IRSA) {
|
||||||
|
expected := []expectedResource{
|
||||||
|
{
|
||||||
|
NamespacedName: types.NamespacedName{Name: "sa-eks-1", Namespace: "kube-system"},
|
||||||
|
f: newServiceAccount,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
NamespacedName: types.NamespacedName{Name: "sa-eks-1", Namespace: "default"},
|
||||||
|
f: newServiceAccount,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
By("Reconciling the created resource")
|
||||||
|
typeNamespacedName := types.NamespacedName{
|
||||||
|
Name: obj.Name,
|
||||||
|
Namespace: obj.Namespace,
|
||||||
|
}
|
||||||
|
_, err := r.Reconcile(ctx, reconcile.Request{
|
||||||
|
NamespacedName: typeNamespacedName,
|
||||||
|
})
|
||||||
|
Expect(err).NotTo(HaveOccurred())
|
||||||
|
checkExist(
|
||||||
|
expectedResource{
|
||||||
|
NamespacedName: types.NamespacedName{Name: "sa-eks-1", Namespace: "kube-system"},
|
||||||
|
f: newServiceAccount,
|
||||||
|
},
|
||||||
|
)
|
||||||
|
f := createCallBackForFixingNamespace(ctx, r, typeNamespacedName, obj)
|
||||||
|
|
||||||
|
By("Add Namespace 'default'")
|
||||||
|
f(obj.Spec.ServiceAccount.Name, []string{"default", "kube-system"})
|
||||||
|
By("Remove Namespace 'kube-system'")
|
||||||
|
f(obj.Spec.ServiceAccount.Name, []string{"default"})
|
||||||
|
checkNoExist(expectedResource{
|
||||||
|
NamespacedName: types.NamespacedName{Name: "sa-eks-1", Namespace: "kube-system"},
|
||||||
|
f: newServiceAccount,
|
||||||
|
})
|
||||||
|
|
||||||
By("removing the custom resource for the Kind")
|
By("removing the custom resource for the Kind")
|
||||||
Eventually(func() error {
|
Eventually(func() error {
|
||||||
return k8sClient.Delete(ctx, obj)
|
return k8sClient.Delete(ctx, obj)
|
||||||
@@ -298,7 +367,20 @@ func newMockIRSASetup() *irsav1alpha1.IRSASetup {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func createCallBack(ctx context.Context, r *IRSAReconciler, typeNamespacedName types.NamespacedName, obj *irsav1alpha1.IRSA) func(name string, namespaces []string) {
|
func newMockIRSASetupForEKS() *irsav1alpha1.IRSASetup {
|
||||||
|
return &irsav1alpha1.IRSASetup{
|
||||||
|
ObjectMeta: metav1.ObjectMeta{
|
||||||
|
Name: "test",
|
||||||
|
Namespace: "default",
|
||||||
|
},
|
||||||
|
Spec: irsav1alpha1.IRSASetupSpec{
|
||||||
|
Mode: irsav1alpha1.ModeEks,
|
||||||
|
IamOIDCProvider: "oidc.example",
|
||||||
|
},
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func createCallBackForFixingNamespace(ctx context.Context, r *IRSAReconciler, typeNamespacedName types.NamespacedName, obj *irsav1alpha1.IRSA) func(name string, namespaces []string) {
|
||||||
return func(name string, namespaces []string) {
|
return func(name string, namespaces []string) {
|
||||||
fixNamespacesAndReconcile(ctx, r, typeNamespacedName, obj, name, namespaces)
|
fixNamespacesAndReconcile(ctx, r, typeNamespacedName, obj, name, namespaces)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -59,13 +59,6 @@ type IRSASetupReconciler struct {
|
|||||||
|
|
||||||
// Reconcile is part of the main kubernetes reconciliation loop which aims to
|
// Reconcile is part of the main kubernetes reconciliation loop which aims to
|
||||||
// move the current state of the cluster closer to the desired state.
|
// move the current state of the cluster closer to the desired state.
|
||||||
// TODO(user): Modify the Reconcile function to compare the state specified by
|
|
||||||
// the IRSASetup object against the actual cluster state, and then
|
|
||||||
// perform operations to make the cluster state reflect the state specified by
|
|
||||||
// the user.
|
|
||||||
//
|
|
||||||
// For more details, check Reconcile and its Result here:
|
|
||||||
// - https://pkg.go.dev/sigs.k8s.io/controller-runtime@v0.16.3/pkg/reconcile
|
|
||||||
func (r *IRSASetupReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ctrl.Result, error) {
|
func (r *IRSASetupReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ctrl.Result, error) {
|
||||||
log := ctrllog.FromContext(ctx)
|
log := ctrllog.FromContext(ctx)
|
||||||
obj := &irsav1alpha1.IRSASetup{}
|
obj := &irsav1alpha1.IRSASetup{}
|
||||||
|
|||||||
@@ -16,6 +16,13 @@ type S3IssuerMeta struct {
|
|||||||
bucketName string
|
bucketName string
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func NewOIDCIssuerMeta(i *irsav1alpha1.IRSASetup) (OIDCIssuerMeta, error) {
|
||||||
|
if i.Spec.Mode == irsav1alpha1.ModeEks {
|
||||||
|
return newIamOIDCProviderIssuerMeta(i.Spec.IamOIDCProvider)
|
||||||
|
}
|
||||||
|
return NewS3IssuerMeta(&i.Spec.Discovery.S3)
|
||||||
|
}
|
||||||
|
|
||||||
func NewS3IssuerMeta(s3 *irsav1alpha1.S3Discovery) (*S3IssuerMeta, error) {
|
func NewS3IssuerMeta(s3 *irsav1alpha1.S3Discovery) (*S3IssuerMeta, error) {
|
||||||
region := s3.Region
|
region := s3.Region
|
||||||
bucketName := s3.BucketName
|
bucketName := s3.BucketName
|
||||||
@@ -32,6 +39,24 @@ func (i *S3IssuerMeta) IssuerHostPath() string {
|
|||||||
// IssuerUrl constructs the URL path for the OIDC issuer based on the provided AWS region and bucket name.
|
// IssuerUrl constructs the URL path for the OIDC issuer based on the provided AWS region and bucket name.
|
||||||
// This utility function generates the expected host path for accessing the OIDC configuration stored in an S3 bucket.
|
// This utility function generates the expected host path for accessing the OIDC configuration stored in an S3 bucket.
|
||||||
func (i *S3IssuerMeta) IssuerUrl() string {
|
func (i *S3IssuerMeta) IssuerUrl() string {
|
||||||
return fmt.Sprintf("https://%s", i.
|
return fmt.Sprintf("https://%s", i.IssuerHostPath())
|
||||||
IssuerHostPath())
|
}
|
||||||
|
|
||||||
|
func newIamOIDCProviderIssuerMeta(providerName string) (*iamOIDCProviderIssuerMeta, error) {
|
||||||
|
if providerName == "" {
|
||||||
|
return nil, fmt.Errorf("IAM OIDC Provider Name must not be empty")
|
||||||
|
}
|
||||||
|
return &iamOIDCProviderIssuerMeta{providerName}, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
type iamOIDCProviderIssuerMeta struct {
|
||||||
|
providerName string
|
||||||
|
}
|
||||||
|
|
||||||
|
func (i *iamOIDCProviderIssuerMeta) IssuerHostPath() string {
|
||||||
|
return i.providerName
|
||||||
|
}
|
||||||
|
|
||||||
|
func (i *iamOIDCProviderIssuerMeta) IssuerUrl() string {
|
||||||
|
return fmt.Sprintf("https://%s", i.IssuerHostPath())
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user