-
Notifications
You must be signed in to change notification settings - Fork 1.4k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
machines: add the authorized keys for a pool using a machine config
`cluster-config-v1` is being deprecated in favor of global configs [1] and Machine Config Operator needs to drop using the `SSHKey` in install-config [2] to setup the `SSHAuthorizedKeys` for `core` user. This pushes a machineconfig with the `SSHAuthorizedKeys` sourced from [2] for each machinepool, so that Machine Config Operator can drop generating the machineconfig using the `cluster-config-v1` config map in the cluster. [1]: #680 [2]: https://godoc.org/github.com/openshift/installer/pkg/types#InstallConfig
- Loading branch information
1 parent
e8ce3e4
commit 87f5c3d
Showing
4 changed files
with
63 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,46 @@ | ||
package machines | ||
|
||
import ( | ||
"fmt" | ||
|
||
ignv2_2types "github.com/coreos/ignition/config/v2_2/types" | ||
mcfgv1 "github.com/openshift/machine-config-operator/pkg/apis/machineconfiguration.openshift.io/v1" | ||
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" | ||
|
||
"github.com/openshift/installer/pkg/types" | ||
) | ||
|
||
func machineConfigForSSH(pool types.MachinePool, key string) *mcfgv1.MachineConfig { | ||
return &mcfgv1.MachineConfig{ | ||
TypeMeta: metav1.TypeMeta{ | ||
APIVersion: "machineconfiguration.openshift.io/v1", | ||
Kind: "MachineConfig", | ||
}, | ||
ObjectMeta: metav1.ObjectMeta{ | ||
Name: fmt.Sprintf("99-%s-ssh", pool.Name), | ||
Labels: map[string]string{ | ||
"machineconfiguration.openshift.io/role": pool.Name, | ||
}, | ||
}, | ||
Spec: mcfgv1.MachineConfigSpec{ | ||
Config: ignWithAuthorizedKeys("core", []string{key}), | ||
}, | ||
} | ||
} | ||
|
||
func ignWithAuthorizedKeys(user string, keys []string) ignv2_2types.Config { | ||
var ignKeys []ignv2_2types.SSHAuthorizedKey | ||
for _, k := range keys { | ||
ignKeys = append(ignKeys, ignv2_2types.SSHAuthorizedKey(k)) | ||
} | ||
return ignv2_2types.Config{ | ||
Ignition: ignv2_2types.Ignition{ | ||
Version: ignv2_2types.MaxVersion.String(), | ||
}, | ||
Passwd: ignv2_2types.Passwd{ | ||
Users: []ignv2_2types.PasswdUser{{ | ||
Name: user, SSHAuthorizedKeys: ignKeys, | ||
}}, | ||
}, | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters