graph

package
v0.0.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 20, 2026 License: Apache-2.0 Imports: 3 Imported by: 0

Documentation

Overview

Package graph provides an in-memory RBAC permission map for kcp.

The graph is the shared seam between providers and the SCAR HTTP handler: providers (the kcp-native RBAC reconciler, an external/FGA integration, etc.) populate the graph with Grant/Revoke calls, and the handler reads from it via ClustersFor. Providers depend on this package; the SCAR handler depends on this package; nothing in this package depends on either of them.

The package deliberately has no kcp imports so it stays reusable by other consumers (admin tooling, FrontProxy optimisations, future Warrants/Scopes evaluators if those land).

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type AccessEndpointSlice

type AccessEndpointSlice struct {
	// ClusterName is the LogicalCluster identifier.
	ClusterName string `json:"clusterName"`
	// Endpoint is the FrontProxy URL for this cluster.
	Endpoint string `json:"endpoint"`
}

AccessEndpointSlice is a single (cluster name, FrontProxy endpoint) pair returned to a caller.

type Graph

type Graph struct {
	// contains filtered or unexported fields
}

Graph is an in-memory RBAC permission map.

func New

func New() *Graph

New returns a new empty Graph.

func (*Graph) ClustersFor

func (g *Graph) ClustersFor(user string, groups []string) []AccessEndpointSlice

ClustersFor returns the clusters that the given user, with the given group memberships, has access to, paired with each cluster's FrontProxy endpoint.

func (*Graph) Forget

func (g *Graph) Forget(cluster LogicalCluster)

Forget removes a cluster entirely: every subject's access to it, and the cluster's recorded endpoint. Providers should call this when a cluster is deleted from the underlying source so stale endpoints don't accumulate.

func (*Graph) Grant

func (g *Graph) Grant(subject Subject, cluster LogicalCluster, endpoint string)

Grant records that subject has access to cluster, reachable at the given endpoint URL.

func (*Graph) Ready

func (g *Graph) Ready() bool

Ready reports whether the graph has completed its initial sync and is ready to serve accurate queries.

func (*Graph) Revoke

func (g *Graph) Revoke(subject Subject, cluster LogicalCluster)

Revoke removes subject's access to cluster. When no subject can reach the cluster any more, its endpoint is dropped too, so Snapshot does not accumulate entries for clusters nobody can see.

func (*Graph) SetEndpoint

func (g *Graph) SetEndpoint(cluster LogicalCluster, endpoint string)

SetEndpoint updates the URL a cluster is reachable at without touching who can access it. Providers call this when a shard or front-proxy URL moves for a cluster whose bindings are unchanged; without it the graph would keep serving the old URL until the next subject change.

func (*Graph) SetReady

func (g *Graph) SetReady()

SetReady marks the graph as having completed its initial sync.

func (*Graph) Snapshot

func (g *Graph) Snapshot() Snapshot

Snapshot returns a read-consistent, JSON-friendly view of the graph.

type LogicalCluster

type LogicalCluster string

type Snapshot

type Snapshot struct {
	Ready    bool                `json:"ready"`
	Subjects map[string][]string `json:"subjects"` // subject → cluster names
	Clusters map[string]string   `json:"clusters"` // cluster name → endpoint
}

Snapshot is a point-in-time view of the graph for diagnostics.

type Subject

type Subject struct {
	Kind SubjectKind
	Name string
}

func Group

func Group(name string) Subject

func User

func User(name string) Subject

type SubjectKind

type SubjectKind string
const (
	SubjectKindUser  SubjectKind = "User"
	SubjectKindGroup SubjectKind = "Group"
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL