-
Notifications
You must be signed in to change notification settings - Fork 259
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
draft: add namespace scoped operator mode
This adds automation and docs for restricting the operator scope from cluster wide to namespace restricted. Signed-off-by: NymanRobin <[email protected]>
- Loading branch information
1 parent
efae71e
commit 97bf046
Showing
33 changed files
with
1,876 additions
and
115 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,47 @@ | ||
apiVersion: kustomize.config.k8s.io/v1beta1 | ||
kind: Kustomization | ||
|
||
resources: | ||
- ../e2e | ||
|
||
# The subjects and roleRef needs to be update here otherwise we lose name-prefix | ||
# This is of course not ideal if the name-prefix changes | ||
patchesStrategicMerge: | ||
- namespaced-manager-patch.yaml | ||
- | | ||
apiVersion: rbac.authorization.k8s.io/v1 | ||
kind: ClusterRoleBinding | ||
metadata: | ||
name: baremetal-operator-manager-rolebinding | ||
roleRef: | ||
kind: Role | ||
name: baremetal-operator-manager-role | ||
subjects: | ||
- kind: ServiceAccount | ||
name: baremetal-operator-controller-manager | ||
namespace: baremetal-operator-system | ||
patches: | ||
- patch: | | ||
# Add a namespace to watch | ||
- op: replace | ||
path: /kind | ||
value: RoleBinding | ||
target: | ||
group: rbac.authorization.k8s.io | ||
kind: ClusterRoleBinding | ||
name: baremetal-operator-manager-rolebinding | ||
|
||
- patch: | | ||
# Add a namespace to watch | ||
- op: replace | ||
path: /kind | ||
value: Role | ||
target: | ||
group: rbac.authorization.k8s.io | ||
kind: ClusterRole | ||
name: baremetal-operator-manager-role | ||
|
||
transformers: | ||
- roles-ns-annotator.yaml |
13 changes: 13 additions & 0 deletions
13
config/overlays/namespaced-e2e/namespaced-manager-patch.yaml
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,13 @@ | ||
apiVersion: apps/v1 | ||
kind: Deployment | ||
metadata: | ||
name: controller-manager | ||
namespace: system | ||
spec: | ||
template: | ||
spec: | ||
containers: | ||
- env: | ||
- name: WATCH_NAMESPACE | ||
value: basic-ops-test,external-inspection-test,inspection-test,live-iso-ops-test,provisioning-ops-test,re-inspection-test | ||
name: manager |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,14 @@ | ||
apiVersion: transformers.example.co/v1 | ||
kind: ValueAnnotator | ||
metadata: | ||
annotations: | ||
config.kubernetes.io/function: "container:\n image: bmo/roleannotator:1.0.0\ | ||
\ \n" | ||
name: notImportantHere | ||
values: | ||
- basic-ops-test | ||
- external-inspection-test | ||
- inspection-test | ||
- live-iso-ops-test | ||
- provisioning-ops-test | ||
- re-inspection-test |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,47 @@ | ||
apiVersion: kustomize.config.k8s.io/v1beta1 | ||
kind: Kustomization | ||
|
||
resources: | ||
- ../../default | ||
|
||
# The subjects and roleRef needs to be update here otherwise we lose name-prefix | ||
# This is of course not ideal if the name-prefix changes | ||
patchesStrategicMerge: | ||
- namespaced-manager-patch.yaml | ||
- | | ||
apiVersion: rbac.authorization.k8s.io/v1 | ||
kind: ClusterRoleBinding | ||
metadata: | ||
name: baremetal-operator-manager-rolebinding | ||
roleRef: | ||
kind: Role | ||
name: baremetal-operator-manager-role | ||
subjects: | ||
- kind: ServiceAccount | ||
name: baremetal-operator-controller-manager | ||
namespace: baremetal-operator-system | ||
patches: | ||
- patch: | | ||
# Add a namespace to watch | ||
- op: replace | ||
path: /kind | ||
value: RoleBinding | ||
target: | ||
group: rbac.authorization.k8s.io | ||
kind: ClusterRoleBinding | ||
name: baremetal-operator-manager-rolebinding | ||
|
||
- patch: | | ||
# Add a namespace to watch | ||
- op: replace | ||
path: /kind | ||
value: Role | ||
target: | ||
group: rbac.authorization.k8s.io | ||
kind: ClusterRole | ||
name: baremetal-operator-manager-role | ||
|
||
transformers: | ||
- roles-ns-annotator.yaml |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,13 @@ | ||
apiVersion: apps/v1 | ||
kind: Deployment | ||
metadata: | ||
name: controller-manager | ||
namespace: system | ||
spec: | ||
template: | ||
spec: | ||
containers: | ||
- env: | ||
- name: WATCH_NAMESPACE | ||
value: basic-ops-test,external-inspection-test,inspection-test,live-iso-ops-test,provisioning-ops-test,re-inspection-test | ||
name: manager |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,14 @@ | ||
apiVersion: transformers.example.co/v1 | ||
kind: ValueAnnotator | ||
metadata: | ||
annotations: | ||
config.kubernetes.io/function: "container:\n image: bmo/roleannotator:1.0.0\ | ||
\ \n" | ||
name: notImportantHere | ||
values: | ||
- basic-ops-test | ||
- external-inspection-test | ||
- inspection-test | ||
- live-iso-ops-test | ||
- provisioning-ops-test | ||
- re-inspection-test |
Oops, something went wrong.