mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
add IRSA api
This commit is contained in:
@@ -0,0 +1,83 @@
|
||||
---
|
||||
apiVersion: apiextensions.k8s.io/v1
|
||||
kind: CustomResourceDefinition
|
||||
metadata:
|
||||
annotations:
|
||||
controller-gen.kubebuilder.io/version: v0.14.0
|
||||
name: irsas.irsa.kkb0318.github.io
|
||||
spec:
|
||||
group: irsa.kkb0318.github.io
|
||||
names:
|
||||
kind: IRSA
|
||||
listKind: IRSAList
|
||||
plural: irsas
|
||||
singular: irsa
|
||||
scope: Namespaced
|
||||
versions:
|
||||
- name: v1alpha1
|
||||
schema:
|
||||
openAPIV3Schema:
|
||||
description: IRSA is the Schema for the irsas API
|
||||
properties:
|
||||
apiVersion:
|
||||
description: |-
|
||||
APIVersion defines the versioned schema of this representation of an object.
|
||||
Servers should convert recognized schemas to the latest internal value, and
|
||||
may reject unrecognized values.
|
||||
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
||||
type: string
|
||||
kind:
|
||||
description: |-
|
||||
Kind is a string value representing the REST resource this object represents.
|
||||
Servers may infer this from the endpoint the client submits requests to.
|
||||
Cannot be updated.
|
||||
In CamelCase.
|
||||
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||
type: string
|
||||
metadata:
|
||||
type: object
|
||||
spec:
|
||||
description: IRSASpec defines the desired state of IRSA
|
||||
properties:
|
||||
iamPolicies:
|
||||
description: IamPolicies represents the list of IAM policies to be
|
||||
attached to the IAM role
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
iamRole:
|
||||
description: IamRole represents the IAM role details associated with
|
||||
the IRSA
|
||||
properties:
|
||||
create:
|
||||
description: Create specifies whether to create the IAM role or
|
||||
not
|
||||
type: boolean
|
||||
name:
|
||||
description: Name represents the name of the IAM role
|
||||
type: string
|
||||
type: object
|
||||
serviceAccount:
|
||||
description: ServiceAccount represents the Kubernetes service account
|
||||
associated with the IRSA
|
||||
properties:
|
||||
name:
|
||||
description: Name represents the name of the Kubernetes service
|
||||
account
|
||||
type: string
|
||||
namespaces:
|
||||
description: Namespaces represents the list of namespaces where
|
||||
the service account is used
|
||||
items:
|
||||
type: string
|
||||
type: array
|
||||
type: object
|
||||
type: object
|
||||
status:
|
||||
description: IRSAStatus defines the observed state of IRSA
|
||||
type: object
|
||||
type: object
|
||||
served: true
|
||||
storage: true
|
||||
subresources:
|
||||
status: {}
|
||||
@@ -3,17 +3,20 @@
|
||||
# It should be run by config/default
|
||||
resources:
|
||||
- bases/irsa.kkb0318.github.io_irsasetups.yaml
|
||||
- bases/irsa.kkb0318.github.io_irsas.yaml
|
||||
#+kubebuilder:scaffold:crdkustomizeresource
|
||||
|
||||
patches:
|
||||
# [WEBHOOK] To enable webhook, uncomment all the sections with [WEBHOOK] prefix.
|
||||
# patches here are for enabling the conversion webhook for each CRD
|
||||
#- path: patches/webhook_in_irsasetups.yaml
|
||||
#- path: patches/webhook_in_irsas.yaml
|
||||
#+kubebuilder:scaffold:crdkustomizewebhookpatch
|
||||
|
||||
# [CERTMANAGER] To enable cert-manager, uncomment all the sections with [CERTMANAGER] prefix.
|
||||
# patches here are for enabling the CA injection for each CRD
|
||||
#- path: patches/cainjection_in_irsasetups.yaml
|
||||
#- path: patches/cainjection_in_irsas.yaml
|
||||
#+kubebuilder:scaffold:crdkustomizecainjectionpatch
|
||||
|
||||
# [WEBHOOK] To enable webhook, uncomment the following section
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
# permissions for end users to edit irsas.
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/name: clusterrole
|
||||
app.kubernetes.io/instance: irsa-editor-role
|
||||
app.kubernetes.io/component: rbac
|
||||
app.kubernetes.io/created-by: irsa-manager
|
||||
app.kubernetes.io/part-of: irsa-manager
|
||||
app.kubernetes.io/managed-by: kustomize
|
||||
name: irsa-editor-role
|
||||
rules:
|
||||
- apiGroups:
|
||||
- irsa.kkb0318.github.io
|
||||
resources:
|
||||
- irsas
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
- apiGroups:
|
||||
- irsa.kkb0318.github.io
|
||||
resources:
|
||||
- irsas/status
|
||||
verbs:
|
||||
- get
|
||||
@@ -0,0 +1,27 @@
|
||||
# permissions for end users to view irsas.
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRole
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/name: clusterrole
|
||||
app.kubernetes.io/instance: irsa-viewer-role
|
||||
app.kubernetes.io/component: rbac
|
||||
app.kubernetes.io/created-by: irsa-manager
|
||||
app.kubernetes.io/part-of: irsa-manager
|
||||
app.kubernetes.io/managed-by: kustomize
|
||||
name: irsa-viewer-role
|
||||
rules:
|
||||
- apiGroups:
|
||||
- irsa.kkb0318.github.io
|
||||
resources:
|
||||
- irsas
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- irsa.kkb0318.github.io
|
||||
resources:
|
||||
- irsas/status
|
||||
verbs:
|
||||
- get
|
||||
@@ -76,6 +76,32 @@ rules:
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
- apiGroups:
|
||||
- irsa.kkb0318.github.io
|
||||
resources:
|
||||
- irsas
|
||||
verbs:
|
||||
- create
|
||||
- delete
|
||||
- get
|
||||
- list
|
||||
- patch
|
||||
- update
|
||||
- watch
|
||||
- apiGroups:
|
||||
- irsa.kkb0318.github.io
|
||||
resources:
|
||||
- irsas/finalizers
|
||||
verbs:
|
||||
- update
|
||||
- apiGroups:
|
||||
- irsa.kkb0318.github.io
|
||||
resources:
|
||||
- irsas/status
|
||||
verbs:
|
||||
- get
|
||||
- patch
|
||||
- update
|
||||
- apiGroups:
|
||||
- irsa.kkb0318.github.io
|
||||
resources:
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
apiVersion: irsa.kkb0318.github.io/v1alpha1
|
||||
kind: IRSA
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/name: irsa
|
||||
app.kubernetes.io/instance: irsa-sample
|
||||
app.kubernetes.io/part-of: irsa-manager
|
||||
app.kubernetes.io/managed-by: kustomize
|
||||
app.kubernetes.io/created-by: irsa-manager
|
||||
name: irsa-sample
|
||||
spec:
|
||||
# TODO(user): Add fields here
|
||||
@@ -1,4 +1,5 @@
|
||||
## Append samples of your project ##
|
||||
resources:
|
||||
- irsa_v1alpha1_irsasetup.yaml
|
||||
- irsa_v1alpha1_irsa.yaml
|
||||
#+kubebuilder:scaffold:manifestskustomizesamples
|
||||
|
||||
Reference in New Issue
Block a user