Documentation
¶
Overview ¶
Package bootstrap installs the kcp-side objects the access virtual workspace needs and verifies they came up.
Index ¶
- Constants
- func CreateWorkspacePath(ctx context.Context, cfg *rest.Config, path, workspaceType string) (*rest.Config, error)
- func JoinWorkspacePath(prefix, leaf string) (string, error)
- func ParseWorkspacePath(path string) ([]string, error)
- func VerifyAPIBinding(ctx context.Context, cfg *rest.Config, bindingName string) error
- type Options
- type Result
Constants ¶
const ( // ControllerNamespace is the namespace inside the APIExport's // workspace holding the server's identity and generated kubeconfig. ControllerNamespace = "default" // ControllerServiceAccount is the identity the server runs as. It lives // in the same workspace as the APIExport so the server never needs an // admin kubeconfig. ControllerServiceAccount = "access-vw-controller" // ControllerTokenSecret is the ServiceAccount token secret kcp // populates. ControllerTokenSecret = "access-vw-controller-token" // ControllerKubeconfigSecret holds the kubeconfig built from that // token, for the server to mount. ControllerKubeconfigSecret = "access-vw-kubeconfig" // ControllerClusterRole is the role carrying everything the server needs // in this workspace, including the verb=access rule that gates the rest. ControllerClusterRole = "access-vw-controller" // ServerIdentityBinding binds ControllerClusterRole to identities named by // Options.ServerUsers/ServerGroups. Separate from the committed binding // because those names are deployment-specific. ServerIdentityBinding = "access-vw-controller-server" )
const ( // DefaultWorkspacePrefix is the parent path the leaf is created under. DefaultWorkspacePrefix = "root:access" // DefaultControllersWorkspace is the leaf workspace this component owns. DefaultControllersWorkspace = "controllers" )
The APIExport lands in <prefix>:<leaf>, both configurable so a deployment can bring its own tree. The default is root:access:controllers.
const APIExportName = "access.contrib.kcp.io"
APIExportName is the APIExport, and the APIExportEndpointSlice, this component installs and serves.
const DefaultWorkspaceType = "universal"
DefaultWorkspaceType is the WorkspaceType used for workspaces this bootstrap creates. "universal" is the plain, unopinionated type; a deployment wanting something else passes --workspace-type.
Variables ¶
This section is empty.
Functions ¶
func CreateWorkspacePath ¶
func CreateWorkspacePath(ctx context.Context, cfg *rest.Config, path, workspaceType string) (*rest.Config, error)
CreateWorkspacePath creates every workspace along path that does not exist yet and returns a config addressing the leaf. Requires rights to create workspaces from root down.
func JoinWorkspacePath ¶
JoinWorkspacePath composes a prefix and leaf into an absolute path, tolerating a prefix given with kubectl-ws style leading colons.
func ParseWorkspacePath ¶
ParseWorkspacePath normalises a kcp workspace path, accepting both the kubectl-ws style ":root:access:magic" and the plain "root:access:magic". It returns the segments, of which the first must be "root".
Types ¶
type Options ¶
type Options struct {
// WorkspacePath is the absolute path the objects were installed
// into, used only for reporting.
WorkspacePath string
// HostOverride replaces the scheme://host[:port] of the generated
// kubeconfig, keeping the workspace path. Needed when init runs with
// an externally reachable URL but the server will connect from inside
// the cluster (or the reverse).
HostOverride string
// ServerUsers and ServerGroups are extra identities to grant the
// controller role to, for deployments that run the server as something
// other than the ServiceAccount minted here -- kcp-operator mounts a
// client certificate, so its server arrives as a User.
//
// Empty means only the ServiceAccount is granted, which is correct when
// the server uses the generated kubeconfig.
ServerUsers []string
ServerGroups []string
// Timeout bounds the apply-and-verify loop.
Timeout time.Duration
}
Options configures Bootstrap.
type Result ¶
type Result struct {
// WorkspacePath is the absolute path of the workspace the objects
// were installed into.
WorkspacePath string
// APIExportEndpointSlice is the name to pass to the server's
// --apiexport-endpointslice flag.
APIExportEndpointSlice string
// VirtualWorkspaceURLs are the per-shard URLs the slice resolved to.
// Empty means the provider will discover nothing.
VirtualWorkspaceURLs []string
// ExportsClusterRef is the logical cluster ID of the workspace the
// APIExport landed in, which is what a consumer APIBinding must
// reference. Reported because the workspace is configurable, so no
// committed example can carry it.
ExportsClusterRef string
// KubeconfigSecret is the Secret, in the APIExport's workspace, holding
// the kubeconfig the server should run with.
KubeconfigSecret string
}
Result reports what a successful bootstrap produced, so callers can print the values the server needs.