mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
deployment image
This commit is contained in:
@@ -136,9 +136,10 @@ func IsSelfHostedReadyConditionTrue(irsa IRSASetup) bool {
|
|||||||
type SelfHostedReason string
|
type SelfHostedReason string
|
||||||
|
|
||||||
const (
|
const (
|
||||||
SelfHostedReasonFailedOidc SelfHostedReason = "SelfHostedSetupFailedOidcCreation"
|
SelfHostedReasonFailedWebhook SelfHostedReason = "SelfHostedSetupFailedWebhookCreation"
|
||||||
SelfHostedReasonFailedKeys SelfHostedReason = "SelfHostedSetupFailedKeysCreation"
|
SelfHostedReasonFailedOidc SelfHostedReason = "SelfHostedSetupFailedOidcCreation"
|
||||||
SelfHostedReasonReady SelfHostedReason = "SelfHostedSetupReady"
|
SelfHostedReasonFailedKeys SelfHostedReason = "SelfHostedSetupFailedKeysCreation"
|
||||||
|
SelfHostedReasonReady SelfHostedReason = "SelfHostedSetupReady"
|
||||||
)
|
)
|
||||||
|
|
||||||
//+kubebuilder:object:root=true
|
//+kubebuilder:object:root=true
|
||||||
|
|||||||
@@ -18,6 +18,7 @@ package controller
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"errors"
|
||||||
|
|
||||||
"k8s.io/apimachinery/pkg/runtime"
|
"k8s.io/apimachinery/pkg/runtime"
|
||||||
ctrl "sigs.k8s.io/controller-runtime"
|
ctrl "sigs.k8s.io/controller-runtime"
|
||||||
@@ -152,7 +153,9 @@ func (r *IRSASetupReconciler) reconcileDelete(ctx context.Context, obj *irsav1al
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
controllerutil.RemoveFinalizer(obj, irsamanagerFinalizer)
|
if !controllerutil.RemoveFinalizer(obj, irsamanagerFinalizer) {
|
||||||
|
return errors.New("failed to remove finalizer")
|
||||||
|
}
|
||||||
return r.Update(ctx, obj)
|
return r.Update(ctx, obj)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -185,17 +188,14 @@ func reconcileSelfhosted(ctx context.Context, obj *irsav1alpha1.IRSASetup, awsCl
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
kubeHandler := handler.NewKubernetesHandler(kubeClient)
|
kubeHandlerForOidc := handler.NewKubernetesHandler(kubeClient)
|
||||||
kubeHandler.Append(secret)
|
kubeHandlerForOidc.Append(secret)
|
||||||
|
|
||||||
// for webhook setup
|
// for webhook setup
|
||||||
webhookSetup, err := webhook.NewWebHookSetup()
|
webhookSetup, err := webhook.NewWebHookSetup()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
for _, r := range webhookSetup.Resources() {
|
|
||||||
kubeHandler.Append(r)
|
|
||||||
}
|
|
||||||
|
|
||||||
var e error
|
var e error
|
||||||
var reason irsav1alpha1.SelfHostedReason
|
var reason irsav1alpha1.SelfHostedReason
|
||||||
@@ -217,15 +217,26 @@ func reconcileSelfhosted(ctx context.Context, obj *irsav1alpha1.IRSASetup, awsCl
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
if forceUpdate {
|
if forceUpdate {
|
||||||
err = kubeHandler.ApplyAll(ctx)
|
err = kubeHandlerForOidc.ApplyAll(ctx)
|
||||||
} else {
|
} else {
|
||||||
err = kubeHandler.CreateAll(ctx)
|
err = kubeHandlerForOidc.CreateAll(ctx)
|
||||||
}
|
}
|
||||||
if err != nil {
|
if err != nil {
|
||||||
e = err
|
e = err
|
||||||
reason = irsav1alpha1.SelfHostedReasonFailedKeys
|
reason = irsav1alpha1.SelfHostedReasonFailedKeys
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
// for webhook update
|
||||||
|
kubeHandlerForWebhook := handler.NewKubernetesHandler(kubeClient)
|
||||||
|
for _, r := range webhookSetup.Resources() {
|
||||||
|
kubeHandlerForWebhook.Append(r)
|
||||||
|
}
|
||||||
|
err = kubeHandlerForWebhook.ApplyAll(ctx)
|
||||||
|
if err != nil {
|
||||||
|
e = err
|
||||||
|
reason = irsav1alpha1.SelfHostedReasonFailedWebhook
|
||||||
|
return err
|
||||||
|
}
|
||||||
*obj = irsav1alpha1.SetupSelfHostedStatusReady(*obj, string(irsav1alpha1.SelfHostedReasonReady), "successfully setup resources for self-hosted")
|
*obj = irsav1alpha1.SetupSelfHostedStatusReady(*obj, string(irsav1alpha1.SelfHostedReasonReady), "successfully setup resources for self-hosted")
|
||||||
log.Info("the self-hosted resources have successfully set up")
|
log.Info("the self-hosted resources have successfully set up")
|
||||||
return nil
|
return nil
|
||||||
|
|||||||
@@ -111,8 +111,9 @@ func (b *baseManifestFactory) deployment() *appsv1.Deployment {
|
|||||||
ServiceAccountName: b.serviceAccountMeta.Name,
|
ServiceAccountName: b.serviceAccountMeta.Name,
|
||||||
Containers: []corev1.Container{
|
Containers: []corev1.Container{
|
||||||
{
|
{
|
||||||
Name: "pod-identity-webhook",
|
Name: "pod-identity-webhook",
|
||||||
Image: "quay.io/amis/pod-identity-webhook:v0.0.1",
|
Image: "amazon/amazon-eks-pod-identity-webhook:latest",
|
||||||
|
|
||||||
ImagePullPolicy: corev1.PullAlways,
|
ImagePullPolicy: corev1.PullAlways,
|
||||||
// Command: []string{}, // Command must be patched
|
// Command: []string{}, // Command must be patched
|
||||||
VolumeMounts: []corev1.VolumeMount{
|
VolumeMounts: []corev1.VolumeMount{
|
||||||
|
|||||||
+5
-1
@@ -16,7 +16,7 @@ spec:
|
|||||||
serviceAccountName: pod-identity-webhook
|
serviceAccountName: pod-identity-webhook
|
||||||
containers:
|
containers:
|
||||||
- name: pod-identity-webhook
|
- name: pod-identity-webhook
|
||||||
image: quay.io/amis/pod-identity-webhook:v0.0.1
|
image: amazon/amazon-eks-pod-identity-webhook:latest
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: Always
|
||||||
# command:
|
# command:
|
||||||
# - /webhook
|
# - /webhook
|
||||||
@@ -31,3 +31,7 @@ spec:
|
|||||||
- name: cert
|
- name: cert
|
||||||
mountPath: /etc/webhook/certs
|
mountPath: /etc/webhook/certs
|
||||||
readOnly: true
|
readOnly: true
|
||||||
|
# volumes:
|
||||||
|
# - name: cert
|
||||||
|
# secret:
|
||||||
|
# secretName: pod-identity-webhook
|
||||||
|
|||||||
Reference in New Issue
Block a user