config

package
v1.26.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 2, 2026 License: Apache-2.0 Imports: 32 Imported by: 0

Documentation

Index

Constants

View Source
const (
	Head = "head"

	DefaultTLSKeyFile = "/tls/tls.key"
	DefaultTLSCrtFile = "/tls/tls.crt"

	ContainerNameSpiceDB = "spicedb"
)

Variables

This section is empty.

Functions

func ApplyPatches added in v1.2.0

func ApplyPatches[K any](object, out K, patches []v1alpha1.Patch, resolver PatchMetaResolver) (int, bool, error)

ApplyPatches applies a set of patches to an object. It returns the number of patches applied, a bool indicating whether there were matching patches and the input differed from the output, and any errors that occurred.

resolver is only consulted for strategic merge patches, which need the apiserver's schema to determine merge keys. json6902 patches and clusters with no patches never touch it, so it is passed as a resolver and consulted on demand rather than resolved eagerly at operator startup.

func NewConfig

func NewConfig(cluster *v1alpha1.SpiceDBCluster, globalConfig *OperatorConfig, secrets map[string]*corev1.Secret, resolver PatchMetaResolver) (*Config, Warning, error)

NewConfig checks that the values in the config + the secrets are sane

Types

type Config

type Config struct {
	MigrationConfig
	SpiceConfig
	Patches []v1alpha1.Patch
	// PatchMeta resolves strategic merge metadata on demand; see ApplyPatches.
	PatchMeta PatchMetaResolver
}

Config holds all values required to create and manage a cluster. Note: The config object holds values from referenced secrets for hashing purposes; these should not be used directly (instead the secret should be mounted)

func (*Config) Deployment

func (c *Config) Deployment(migrationHash, secretHash string) *applyappsv1.DeploymentApplyConfiguration

func (*Config) MigrationJob

func (c *Config) MigrationJob(migrationHash string) *applybatchv1.JobApplyConfiguration

func (*Config) PodDisruptionBudget added in v1.21.0

func (*Config) Role

func (*Config) RoleBinding

func (*Config) Service

func (*Config) ServiceAccount

type MigrationConfig

type MigrationConfig struct {
	TargetMigration        string
	TargetPhase            string
	MigrationLogLevel      string
	DatastoreEngine        string
	DatastoreURI           string
	SpannerCredsSecretRef  string
	TargetSpiceDBImage     string
	EnvPrefix              string
	SpiceDBCmd             string
	DatastoreTLSSecretName string
	SpiceDBVersion         *v1alpha1.SpiceDBVersion
}

MigrationConfig stores data that is relevant for running migrations or deciding if migrations need to be run

type OperatorConfig added in v1.0.0

type OperatorConfig struct {
	ImageName string `json:"imageName,omitempty"`
	updates.UpdateGraph
}

OperatorConfig holds operator-wide config that is used across all objects

func NewOperatorConfig added in v1.1.0

func NewOperatorConfig() OperatorConfig

func (OperatorConfig) Copy added in v1.0.0

func (o OperatorConfig) Copy() OperatorConfig

type PDBConfig added in v1.26.0

type PDBConfig struct {
	Disabled       bool
	MaxUnavailable *intstr.IntOrString
	MinAvailable   *intstr.IntOrString
}

PDBConfig holds the configuration for the PodDisruptionBudget.

type PatchMetaResolver added in v1.26.1

type PatchMetaResolver interface {
	LookupPatchMeta(gvk schema.GroupVersionKind) (strategicpatch.LookupPatchMeta, error)
}

PatchMetaResolver supplies the strategic merge metadata for a kind: the merge keys and patch strategies that decide whether a list in a patch is merged with the existing list or replaces it wholesale.

Resolution is per-GVK and on demand so that only the group-versions actually patched are ever fetched and parsed. That is what keeps the operator's footprint small: a whole-cluster schema costs ~100MiB of retained heap, while the five group-versions this operator patches cost single-digit MiB.

type RawConfig

type RawConfig map[string]any

RawConfig has not been processed/validated yet

func (RawConfig) Pop

func (r RawConfig) Pop(key string) string

type ResolvedCredentialRef added in v1.23.0

type ResolvedCredentialRef struct {
	SecretName string
	Key        string
	Skip       bool
}

ResolvedCredentialRef is a credential source after defaults have been applied.

type SpiceConfig

type SpiceConfig struct {
	LogLevel                       string
	SkipMigrations                 bool
	Name                           string
	Namespace                      string
	UID                            string
	Replicas                       int32
	PresharedKey                   string
	EnvPrefix                      string
	SpiceDBCmd                     string
	TLSSecretName                  string
	SkipTLSWarning                 bool
	DispatchEnabled                bool
	DispatchUpstreamCASecretName   string
	DispatchUpstreamCASecretPath   string
	TelemetryTLSCASecretName       string
	DatastoreURIRef                ResolvedCredentialRef
	PresharedKeyRef                ResolvedCredentialRef
	MigrationSecretsRef            ResolvedCredentialRef
	ExtraPodLabels                 map[string]string
	ExtraPodAnnotations            map[string]string
	ExtraServiceAccountAnnotations map[string]string
	ServiceAccountName             string
	ProjectLabels                  bool
	ProjectAnnotations             bool
	Passthrough                    map[string]string
	PDB                            PDBConfig
}

SpiceConfig contains config relevant to running spicedb or determining if spicedb needs to be updated

type V3PatchMetaResolver added in v1.26.1

type V3PatchMetaResolver struct {
	// contains filtered or unexported fields
}

V3PatchMetaResolver resolves patch metadata from the apiserver's OpenAPI v3 endpoints, fetching and indexing one group-version at a time and caching the result for the lifetime of the resolver.

func NewV3PatchMetaResolver added in v1.26.1

func NewV3PatchMetaResolver(root openapi3.Root) *V3PatchMetaResolver

func (*V3PatchMetaResolver) LookupPatchMeta added in v1.26.1

type Warning

type Warning error

Warning is an issue with configuration that we will report as undesirable but which don't prevent the cluster from starting (i.e. no TLS config)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL