|
| 1 | +diff --git a/pkg/operator/resources/cluster/apiserver.go b/pkg/operator/resources/cluster/apiserver.go |
| 2 | +index 5e8432713..adf8093fa 100644 |
| 3 | +--- a/pkg/operator/resources/cluster/apiserver.go |
| 4 | ++++ b/pkg/operator/resources/cluster/apiserver.go |
| 5 | +@@ -215,7 +215,7 @@ func createDataImportCronValidatingWebhook(namespace string, c client.Client, l |
| 6 | + Kind: "ValidatingWebhookConfiguration", |
| 7 | + }, |
| 8 | + ObjectMeta: metav1.ObjectMeta{ |
| 9 | +- Name: "cdi-api-dataimportcron-validate", |
| 10 | ++ Name: "cdi-internal-virtualization-api-dataimportcron-validate", |
| 11 | + Labels: map[string]string{ |
| 12 | + utils.CDILabel: apiServerServiceName, |
| 13 | + }, |
| 14 | +@@ -282,7 +282,7 @@ func createPopulatorsValidatingWebhook(namespace string, c client.Client, l logr |
| 15 | + Kind: "ValidatingWebhookConfiguration", |
| 16 | + }, |
| 17 | + ObjectMeta: metav1.ObjectMeta{ |
| 18 | +- Name: "cdi-api-populator-validate", |
| 19 | ++ Name: "cdi-internal-virtualization-api-populator-validate", |
| 20 | + Labels: map[string]string{ |
| 21 | + utils.CDILabel: apiServerServiceName, |
| 22 | + }, |
| 23 | +@@ -349,7 +349,7 @@ func createDataVolumeValidatingWebhook(namespace string, c client.Client, l logr |
| 24 | + Kind: "ValidatingWebhookConfiguration", |
| 25 | + }, |
| 26 | + ObjectMeta: metav1.ObjectMeta{ |
| 27 | +- Name: "cdi-api-datavolume-validate", |
| 28 | ++ Name: "cdi-internal-virtualization-api-datavolume-validate", |
| 29 | + Labels: map[string]string{ |
| 30 | + utils.CDILabel: apiServerServiceName, |
| 31 | + }, |
| 32 | +@@ -416,7 +416,7 @@ func createCDIValidatingWebhook(namespace string, c client.Client, l logr.Logger |
| 33 | + Kind: "ValidatingWebhookConfiguration", |
| 34 | + }, |
| 35 | + ObjectMeta: metav1.ObjectMeta{ |
| 36 | +- Name: "cdi-api-validate", |
| 37 | ++ Name: "cdi-internal-virtualization-api-validate", |
| 38 | + Labels: map[string]string{ |
| 39 | + utils.CDILabel: apiServerServiceName, |
| 40 | + }, |
| 41 | +@@ -485,7 +485,7 @@ func createObjectTransferValidatingWebhook(namespace string, c client.Client, l |
| 42 | + Kind: "ValidatingWebhookConfiguration", |
| 43 | + }, |
| 44 | + ObjectMeta: metav1.ObjectMeta{ |
| 45 | +- Name: "objecttransfer-api-validate", |
| 46 | ++ Name: "cdi-internal-virtualization-objecttransfer-api-validate", |
| 47 | + Labels: map[string]string{ |
| 48 | + utils.CDILabel: apiServerServiceName, |
| 49 | + }, |
| 50 | +@@ -558,7 +558,7 @@ func createDataVolumeMutatingWebhook(namespace string, c client.Client, l logr.L |
| 51 | + Kind: "MutatingWebhookConfiguration", |
| 52 | + }, |
| 53 | + ObjectMeta: metav1.ObjectMeta{ |
| 54 | +- Name: "cdi-api-datavolume-mutate", |
| 55 | ++ Name: "cdi-internal-virtualization-api-datavolume-mutate", |
| 56 | + Labels: map[string]string{ |
| 57 | + utils.CDILabel: apiServerServiceName, |
| 58 | + }, |
| 59 | +@@ -626,10 +626,12 @@ func getAPIServerCABundle(namespace string, c client.Client, l logr.Logger) []by |
| 60 | + return nil |
| 61 | + } |
| 62 | + |
| 63 | ++const apiServerWrapName = "cdi-internal-virtualization-apiserver" |
| 64 | ++ |
| 65 | + func createAPIServerClusterRoleBinding(namespace string) *rbacv1.ClusterRoleBinding { |
| 66 | +- return utils.ResourceBuilder.CreateClusterRoleBinding(apiServerResourceName, apiServerResourceName, apiServerResourceName, namespace) |
| 67 | ++ return utils.ResourceBuilder.CreateClusterRoleBinding(apiServerWrapName, apiServerWrapName, apiServerResourceName, namespace) |
| 68 | + } |
| 69 | + |
| 70 | + func createAPIServerClusterRole() *rbacv1.ClusterRole { |
| 71 | +- return utils.ResourceBuilder.CreateClusterRole(apiServerResourceName, getAPIServerClusterPolicyRules()) |
| 72 | ++ return utils.ResourceBuilder.CreateClusterRole(apiServerWrapName, getAPIServerClusterPolicyRules()) |
| 73 | + } |
| 74 | +diff --git a/pkg/operator/resources/cluster/controller.go b/pkg/operator/resources/cluster/controller.go |
| 75 | +index d29b0dd16..875afaf61 100644 |
| 76 | +--- a/pkg/operator/resources/cluster/controller.go |
| 77 | ++++ b/pkg/operator/resources/cluster/controller.go |
| 78 | +@@ -26,6 +26,9 @@ import ( |
| 79 | + const ( |
| 80 | + controllerServiceAccountName = "cdi-sa" |
| 81 | + controlerClusterRoleName = "cdi" |
| 82 | ++ |
| 83 | ++ wrapServiceAccountName = "cdi-internal-virtualization-sa" |
| 84 | ++ wrapClusterRoleName = "cdi-internal-virtualization" |
| 85 | + ) |
| 86 | + |
| 87 | + func createControllerResources(args *FactoryArgs) []client.Object { |
| 88 | +@@ -36,7 +39,7 @@ func createControllerResources(args *FactoryArgs) []client.Object { |
| 89 | + } |
| 90 | + |
| 91 | + func createControllerClusterRoleBinding(namespace string) *rbacv1.ClusterRoleBinding { |
| 92 | +- return utils.ResourceBuilder.CreateClusterRoleBinding(controllerServiceAccountName, controlerClusterRoleName, controllerServiceAccountName, namespace) |
| 93 | ++ return utils.ResourceBuilder.CreateClusterRoleBinding(wrapServiceAccountName, wrapClusterRoleName, controllerServiceAccountName, namespace) |
| 94 | + } |
| 95 | + |
| 96 | + func getControllerClusterPolicyRules() []rbacv1.PolicyRule { |
| 97 | +@@ -257,5 +260,5 @@ func getControllerClusterPolicyRules() []rbacv1.PolicyRule { |
| 98 | + } |
| 99 | + |
| 100 | + func createControllerClusterRole() *rbacv1.ClusterRole { |
| 101 | +- return utils.ResourceBuilder.CreateClusterRole(controlerClusterRoleName, getControllerClusterPolicyRules()) |
| 102 | ++ return utils.ResourceBuilder.CreateClusterRole(wrapClusterRoleName, getControllerClusterPolicyRules()) |
| 103 | + } |
| 104 | +diff --git a/pkg/operator/resources/cluster/cronjob.go b/pkg/operator/resources/cluster/cronjob.go |
| 105 | +index 71b2fa0f7..bf45a6480 100644 |
| 106 | +--- a/pkg/operator/resources/cluster/cronjob.go |
| 107 | ++++ b/pkg/operator/resources/cluster/cronjob.go |
| 108 | +@@ -53,10 +53,12 @@ func getCronJobClusterPolicyRules() []rbacv1.PolicyRule { |
| 109 | + } |
| 110 | + } |
| 111 | + |
| 112 | ++const cronJobWrapName = "cdi-internal-virtualization-cronjob" |
| 113 | ++ |
| 114 | + func createCronJobClusterRoleBinding(namespace string) *rbacv1.ClusterRoleBinding { |
| 115 | +- return utils.ResourceBuilder.CreateClusterRoleBinding(cronJobResourceName, cronJobResourceName, cronJobResourceName, namespace) |
| 116 | ++ return utils.ResourceBuilder.CreateClusterRoleBinding(cronJobWrapName, cronJobWrapName, cronJobResourceName, namespace) |
| 117 | + } |
| 118 | + |
| 119 | + func createCronJobClusterRole() *rbacv1.ClusterRole { |
| 120 | +- return utils.ResourceBuilder.CreateClusterRole(cronJobResourceName, getCronJobClusterPolicyRules()) |
| 121 | ++ return utils.ResourceBuilder.CreateClusterRole(cronJobWrapName, getCronJobClusterPolicyRules()) |
| 122 | + } |
| 123 | +diff --git a/pkg/operator/resources/cluster/rbac.go b/pkg/operator/resources/cluster/rbac.go |
| 124 | +index 264b83891..a2a968b41 100644 |
| 125 | +--- a/pkg/operator/resources/cluster/rbac.go |
| 126 | ++++ b/pkg/operator/resources/cluster/rbac.go |
| 127 | +@@ -26,11 +26,11 @@ import ( |
| 128 | + |
| 129 | + func createAggregateClusterRoles(_ *FactoryArgs) []client.Object { |
| 130 | + return []client.Object{ |
| 131 | +- utils.ResourceBuilder.CreateAggregateClusterRole("cdi.kubevirt.io:admin", "admin", getAdminPolicyRules()), |
| 132 | +- utils.ResourceBuilder.CreateAggregateClusterRole("cdi.kubevirt.io:edit", "edit", getEditPolicyRules()), |
| 133 | +- utils.ResourceBuilder.CreateAggregateClusterRole("cdi.kubevirt.io:view", "view", getViewPolicyRules()), |
| 134 | +- createConfigReaderClusterRole("cdi.kubevirt.io:config-reader"), |
| 135 | +- createConfigReaderClusterRoleBinding("cdi.kubevirt.io:config-reader"), |
| 136 | ++ utils.ResourceBuilder.CreateAggregateClusterRole("cdi.internal.virtualization.deckhouse.io:admin", "admin", getAdminPolicyRules()), |
| 137 | ++ utils.ResourceBuilder.CreateAggregateClusterRole("cdi.internal.virtualization.deckhouse.io:edit", "edit", getEditPolicyRules()), |
| 138 | ++ utils.ResourceBuilder.CreateAggregateClusterRole("cdi.internal.virtualization.deckhouse.io:view", "view", getViewPolicyRules()), |
| 139 | ++ createConfigReaderClusterRole("cdi.internal.virtualization.deckhouse.io:config-reader"), |
| 140 | ++ createConfigReaderClusterRoleBinding("cdi.internal.virtualization.deckhouse.io:config-reader"), |
| 141 | + } |
| 142 | + } |
| 143 | + |
| 144 | +diff --git a/pkg/operator/resources/cluster/uploadproxy.go b/pkg/operator/resources/cluster/uploadproxy.go |
| 145 | +index a9ac62765..e22a871c7 100644 |
| 146 | +--- a/pkg/operator/resources/cluster/uploadproxy.go |
| 147 | ++++ b/pkg/operator/resources/cluster/uploadproxy.go |
| 148 | +@@ -51,10 +51,12 @@ func getUploadProxyClusterPolicyRules() []rbacv1.PolicyRule { |
| 149 | + } |
| 150 | + } |
| 151 | + |
| 152 | ++const uploadProxyWrapName = "cdi-internal-virtualization-uploadproxy" |
| 153 | ++ |
| 154 | + func createUploadProxyClusterRoleBinding(namespace string) *rbacv1.ClusterRoleBinding { |
| 155 | +- return utils.ResourceBuilder.CreateClusterRoleBinding(uploadProxyResourceName, uploadProxyResourceName, uploadProxyResourceName, namespace) |
| 156 | ++ return utils.ResourceBuilder.CreateClusterRoleBinding(uploadProxyWrapName, uploadProxyWrapName, uploadProxyResourceName, namespace) |
| 157 | + } |
| 158 | + |
| 159 | + func createUploadProxyClusterRole() *rbacv1.ClusterRole { |
| 160 | +- return utils.ResourceBuilder.CreateClusterRole(uploadProxyResourceName, getUploadProxyClusterPolicyRules()) |
| 161 | ++ return utils.ResourceBuilder.CreateClusterRole(uploadProxyWrapName, getUploadProxyClusterPolicyRules()) |
| 162 | + } |
| 163 | +diff --git a/pkg/operator/resources/operator/operator.go b/pkg/operator/resources/operator/operator.go |
| 164 | +index 1ad35841f..01ae5e72e 100644 |
| 165 | +--- a/pkg/operator/resources/operator/operator.go |
| 166 | ++++ b/pkg/operator/resources/operator/operator.go |
| 167 | +@@ -129,11 +129,11 @@ func getClusterPolicyRules() []rbacv1.PolicyRule { |
| 168 | + "validatingwebhookconfigurations", |
| 169 | + }, |
| 170 | + ResourceNames: []string{ |
| 171 | +- "cdi-api-dataimportcron-validate", |
| 172 | +- "cdi-api-populator-validate", |
| 173 | +- "cdi-api-datavolume-validate", |
| 174 | +- "cdi-api-validate", |
| 175 | +- "objecttransfer-api-validate", |
| 176 | ++ "cdi-internal-virtualization-api-dataimportcron-validate", |
| 177 | ++ "cdi-internal-virtualization-api-populator-validate", |
| 178 | ++ "cdi-internal-virtualization-api-datavolume-validate", |
| 179 | ++ "cdi-internal-virtualization-api-validate", |
| 180 | ++ "cdi-internal-virtualization-objecttransfer-api-validate", |
| 181 | + }, |
| 182 | + Verbs: []string{ |
| 183 | + "get", |
| 184 | +@@ -149,7 +149,7 @@ func getClusterPolicyRules() []rbacv1.PolicyRule { |
| 185 | + "mutatingwebhookconfigurations", |
| 186 | + }, |
| 187 | + ResourceNames: []string{ |
| 188 | +- "cdi-api-datavolume-mutate", |
| 189 | ++ "cdi-internal-virtualization-api-datavolume-mutate", |
| 190 | + }, |
| 191 | + Verbs: []string{ |
| 192 | + "get", |
0 commit comments