-
Notifications
You must be signed in to change notification settings - Fork 15
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
* refactor: reordered role list, added label * feat: added helper for ReconcilerFunc * feat: added predicates for filtering events to controllers * fix: accesscodes are namespaced * fix: explicitly get rolebinding informer * feat: changed accesscode controller to controller-runtime
- Loading branch information
Showing
12 changed files
with
296 additions
and
86 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,47 +1,43 @@ | ||
package accesscode | ||
|
||
import ( | ||
"context" | ||
"errors" | ||
"github.com/hobbyfarm/gargantua/v4/pkg/apis/hobbyfarm.io/v4alpha1" | ||
"github.com/hobbyfarm/gargantua/v4/pkg/factoryhelpers" | ||
"github.com/rancher/lasso/pkg/client" | ||
"github.com/rancher/lasso/pkg/controller" | ||
"github.com/hobbyfarm/gargantua/v4/pkg/controllers/helpers" | ||
"k8s.io/apimachinery/pkg/runtime" | ||
"sigs.k8s.io/controller-runtime/pkg/builder" | ||
client2 "sigs.k8s.io/controller-runtime/pkg/client" | ||
"sigs.k8s.io/controller-runtime/pkg/manager" | ||
) | ||
|
||
type accessCodeController struct { | ||
roleClient *client.Client | ||
|
||
accessCodeController controller.SharedController | ||
otacController controller.SharedController | ||
kclient client2.Client | ||
scheme *runtime.Scheme | ||
} | ||
|
||
func RegisterHandlers(factory controller.SharedControllerFactory) error { | ||
roleClient, err := factoryhelpers.ClientForObject(&v4alpha1.Role{}, factory) | ||
if err != nil { | ||
return err | ||
func New(mgr manager.Manager) error { | ||
acc := &accessCodeController{ | ||
kclient: mgr.GetClient(), | ||
scheme: mgr.GetScheme(), | ||
} | ||
|
||
acController, err := factory.ForObject(&v4alpha1.AccessCode{}) | ||
if err != nil { | ||
return err | ||
} | ||
errs := make([]error, 0) | ||
|
||
otacController, err := factory.ForObject(&v4alpha1.OneTimeAccessCode{}) | ||
if err != nil { | ||
return err | ||
if err := builder. | ||
ControllerManagedBy(mgr). | ||
Owns(&v4alpha1.Role{}, builder.MatchEveryOwner). | ||
Named("accesscode-role"). | ||
For(&v4alpha1.AccessCode{}).Complete(helpers.ReconcileFunc(acc.ReconcileRole)); err != nil { | ||
errs = append(errs, err) | ||
} | ||
|
||
acc := &accessCodeController{ | ||
roleClient: roleClient, | ||
accessCodeController: acController, | ||
otacController: otacController, | ||
if err := builder. | ||
ControllerManagedBy(mgr). | ||
Owns(&v4alpha1.RoleBinding{}, builder.MatchEveryOwner). | ||
Named("accesscode-rolebinding"). | ||
For(&v4alpha1.AccessCode{}).Complete(helpers.ReconcileFunc(acc.ReconcileRoleBinding)); err != nil { | ||
errs = append(errs, err) | ||
} | ||
|
||
acController.RegisterHandler(context.TODO(), "access-code-ensure-role", | ||
controller.SharedControllerHandlerFunc(acc.ensureRole)) | ||
|
||
otacController.RegisterHandler(context.TODO(), "otac-ensure-role", | ||
controller.SharedControllerHandlerFunc(acc.ensureRole)) | ||
|
||
return nil | ||
return errors.Join(errs...) | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,81 @@ | ||
package accesscode | ||
|
||
import ( | ||
"context" | ||
"github.com/hobbyfarm/gargantua/v4/pkg/apis/hobbyfarm.io/v4alpha1" | ||
labels2 "github.com/hobbyfarm/gargantua/v4/pkg/labels" | ||
"github.com/hobbyfarm/gargantua/v4/pkg/uid" | ||
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" | ||
"log/slog" | ||
"sigs.k8s.io/controller-runtime/pkg/client" | ||
"sigs.k8s.io/controller-runtime/pkg/controller/controllerutil" | ||
"sigs.k8s.io/controller-runtime/pkg/reconcile" | ||
) | ||
|
||
func (acc *accessCodeController) ReconcileRoleBinding(ctx context.Context, request reconcile.Request) (reconcile.Result, error) { | ||
roleBindingList := &v4alpha1.RoleBindingList{} | ||
if err := acc.kclient.List(ctx, roleBindingList, client.MatchingLabels{ | ||
labels2.CodeRoleBindingLabel: request.Name, | ||
}); err != nil { | ||
return reconcile.Result{}, err | ||
} | ||
|
||
ac := &v4alpha1.AccessCode{} | ||
if err := acc.kclient.Get(ctx, request.NamespacedName, ac); err != nil { | ||
return reconcile.Result{}, client.IgnoreNotFound(err) | ||
} | ||
|
||
// Remove to avoid issues with ownership | ||
ac.UID = uid.RemoveUIDPublic(ac.UID) | ||
|
||
var requeue = false | ||
if len(roleBindingList.Items) == 0 { | ||
if err := acc.createRoleBinding(ctx, ac); err != nil { | ||
return reconcile.Result{}, err | ||
} | ||
|
||
requeue = true | ||
} | ||
|
||
if len(roleBindingList.Items) == 1 { | ||
var rolebinding = &roleBindingList.Items[0] | ||
|
||
// set ownership, everything else (membership) is handled elsewhere | ||
if err := controllerutil.SetControllerReference(ac, rolebinding, acc.scheme); err != nil { | ||
return reconcile.Result{}, err | ||
} | ||
|
||
if err := acc.kclient.Update(ctx, rolebinding); err != nil { | ||
return reconcile.Result{}, err | ||
} | ||
} | ||
|
||
if len(roleBindingList.Items) > 1 { | ||
slog.Error("more than one rolebinding exists for accesscode", "accesscode", ac.Name) | ||
} | ||
|
||
return reconcile.Result{Requeue: requeue}, nil | ||
} | ||
|
||
func (acc *accessCodeController) createRoleBinding(ctx context.Context, ac *v4alpha1.AccessCode) error { | ||
slog.Debug("rolebinding does not exist for accesscode, creating it", "accesscode", ac.Name) | ||
rb := &v4alpha1.RoleBinding{ | ||
ObjectMeta: metav1.ObjectMeta{ | ||
GenerateName: "code-", | ||
Labels: map[string]string{ | ||
labels2.CodeRoleBindingLabel: ac.Name, | ||
}, | ||
}, | ||
} | ||
|
||
if err := acc.kclient.Create(ctx, rb); err != nil { | ||
slog.Error("error creating rolebinding for accesscode", "error", err.Error(), | ||
"accesscode", ac.Name) | ||
return err | ||
} | ||
|
||
slog.Debug("created rolebinding for accesscode", "rolebinding", rb.Name, | ||
"accesscode", ac.Name) | ||
|
||
return nil | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.