Documentation
¶
Overview ¶
Package rbac materializes the ClusterRoles and ClusterRoleBindings described by a kcmv1.RBACPolicy into a child cluster. It is invoked by github.com/K0rdent/kcm/internal/controller.ClusterDeploymentReconciler for the single RBACPolicy a ClusterDeployment references via spec.rbacPolicy — there is no dedicated controller in this package, since the sync is just one more step of that reconciler's loop.
Index ¶
Constants ¶
const ( // ManagedByLabelKey / ManagedByLabelValue mark every ClusterRole/ClusterRoleBinding this package // creates in a child cluster, and are what Prune selects on. Deliberately distinct from the // generic kcmv1.KCMManagedLabelKey so a prune here can never touch some other k0rdent-managed // object in the child cluster that isn't part of this RBACPolicy sync. It is also what tells // applyClusterRole a ClusterRole is safe to overwrite. ManagedByLabelKey = "k0rdent.mirantis.com/managed-by" ManagedByLabelValue = "rbac-operator" )
Variables ¶
var ErrTerminal = errors.New("terminal error")
ErrTerminal marks a failure that no amount of retrying can clear — only an RBACPolicy spec edit can. Callers use Retriable to decide whether to requeue.
Functions ¶
func Prune ¶
func Prune(ctx context.Context, childCl client.Client, desiredRoles, desiredBindings map[string]struct{}) (bool, error)
Prune removes ClusterRoles and ClusterRoleBindings previously created by Sync in the child cluster that are no longer present in desiredRoles/desiredBindings, and reports whether anything was actually deleted. Passing nil/empty maps removes everything this package manages there — used both for normal drift cleanup after a Sync, and to tear down everything a ClusterDeployment's child cluster once had once it stops referencing an RBACPolicy at all.
func Retriable ¶
Retriable reports whether err holds at least one failure worth retrying. A ErrTerminal-only error (including a joined one) is not.
func Sync ¶
func Sync(ctx context.Context, childCl client.Client, policy *kcmv1.RBACPolicy) (desiredRoles, desiredBindings map[string]struct{}, changed bool, _ error)
Sync creates/updates the ClusterRoles and ClusterRoleBindings implied by policy's role catalog, and returns the set of object names that are now desired (for use by Prune) and whether anything was actually created or updated. A binding that fails to apply does not stop the rest from being applied; all failures are joined into the returned error.
Types ¶
This section is empty.