add IRSA api

This commit is contained in:
kkb0318
2024-05-15 21:58:49 +09:00
parent 811d295b74
commit a3d160c47c
16 changed files with 647 additions and 5 deletions
@@ -0,0 +1,83 @@
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.14.0
name: irsas.irsa.kkb0318.github.io
spec:
group: irsa.kkb0318.github.io
names:
kind: IRSA
listKind: IRSAList
plural: irsas
singular: irsa
scope: Namespaced
versions:
- name: v1alpha1
schema:
openAPIV3Schema:
description: IRSA is the Schema for the irsas API
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
description: IRSASpec defines the desired state of IRSA
properties:
iamPolicies:
description: IamPolicies represents the list of IAM policies to be
attached to the IAM role
items:
type: string
type: array
iamRole:
description: IamRole represents the IAM role details associated with
the IRSA
properties:
create:
description: Create specifies whether to create the IAM role or
not
type: boolean
name:
description: Name represents the name of the IAM role
type: string
type: object
serviceAccount:
description: ServiceAccount represents the Kubernetes service account
associated with the IRSA
properties:
name:
description: Name represents the name of the Kubernetes service
account
type: string
namespaces:
description: Namespaces represents the list of namespaces where
the service account is used
items:
type: string
type: array
type: object
type: object
status:
description: IRSAStatus defines the observed state of IRSA
type: object
type: object
served: true
storage: true
subresources:
status: {}
+3
View File
@@ -3,17 +3,20 @@
# It should be run by config/default
resources:
- bases/irsa.kkb0318.github.io_irsasetups.yaml
- bases/irsa.kkb0318.github.io_irsas.yaml
#+kubebuilder:scaffold:crdkustomizeresource
patches:
# [WEBHOOK] To enable webhook, uncomment all the sections with [WEBHOOK] prefix.
# patches here are for enabling the conversion webhook for each CRD
#- path: patches/webhook_in_irsasetups.yaml
#- path: patches/webhook_in_irsas.yaml
#+kubebuilder:scaffold:crdkustomizewebhookpatch
# [CERTMANAGER] To enable cert-manager, uncomment all the sections with [CERTMANAGER] prefix.
# patches here are for enabling the CA injection for each CRD
#- path: patches/cainjection_in_irsasetups.yaml
#- path: patches/cainjection_in_irsas.yaml
#+kubebuilder:scaffold:crdkustomizecainjectionpatch
# [WEBHOOK] To enable webhook, uncomment the following section
+31
View File
@@ -0,0 +1,31 @@
# permissions for end users to edit irsas.
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
labels:
app.kubernetes.io/name: clusterrole
app.kubernetes.io/instance: irsa-editor-role
app.kubernetes.io/component: rbac
app.kubernetes.io/created-by: irsa-manager
app.kubernetes.io/part-of: irsa-manager
app.kubernetes.io/managed-by: kustomize
name: irsa-editor-role
rules:
- apiGroups:
- irsa.kkb0318.github.io
resources:
- irsas
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- irsa.kkb0318.github.io
resources:
- irsas/status
verbs:
- get
+27
View File
@@ -0,0 +1,27 @@
# permissions for end users to view irsas.
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
labels:
app.kubernetes.io/name: clusterrole
app.kubernetes.io/instance: irsa-viewer-role
app.kubernetes.io/component: rbac
app.kubernetes.io/created-by: irsa-manager
app.kubernetes.io/part-of: irsa-manager
app.kubernetes.io/managed-by: kustomize
name: irsa-viewer-role
rules:
- apiGroups:
- irsa.kkb0318.github.io
resources:
- irsas
verbs:
- get
- list
- watch
- apiGroups:
- irsa.kkb0318.github.io
resources:
- irsas/status
verbs:
- get
+26
View File
@@ -76,6 +76,32 @@ rules:
- patch
- update
- watch
- apiGroups:
- irsa.kkb0318.github.io
resources:
- irsas
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- irsa.kkb0318.github.io
resources:
- irsas/finalizers
verbs:
- update
- apiGroups:
- irsa.kkb0318.github.io
resources:
- irsas/status
verbs:
- get
- patch
- update
- apiGroups:
- irsa.kkb0318.github.io
resources:
+12
View File
@@ -0,0 +1,12 @@
apiVersion: irsa.kkb0318.github.io/v1alpha1
kind: IRSA
metadata:
labels:
app.kubernetes.io/name: irsa
app.kubernetes.io/instance: irsa-sample
app.kubernetes.io/part-of: irsa-manager
app.kubernetes.io/managed-by: kustomize
app.kubernetes.io/created-by: irsa-manager
name: irsa-sample
spec:
# TODO(user): Add fields here
+1
View File
@@ -1,4 +1,5 @@
## Append samples of your project ##
resources:
- irsa_v1alpha1_irsasetup.yaml
- irsa_v1alpha1_irsa.yaml
#+kubebuilder:scaffold:manifestskustomizesamples