Documentation
¶
Overview ¶
Package server wires the Access Virtual Workspace binary together: the shared access graph, the RBAC provider that populates it, and a virtual-workspace root apiserver (kcp virtual-workspace-framework) serving the access virtual workspace at /services/access behind kcp's front-proxy.
Index ¶
- func Run(ctx context.Context, o *Options) error
- type Authentication
- func (c *Authentication) AddFlags(fs *pflag.FlagSet)
- func (c *Authentication) ApplyTo(ctx context.Context, authenticationInfo *genericapiserver.AuthenticationInfo, ...) error
- func (c *Authentication) OIDCEnabled() bool
- func (c *Authentication) RequestHeaderEnabled() bool
- func (c *Authentication) Validate() []error
- type Options
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
Types ¶
type Authentication ¶
type Authentication struct {
BuiltInOptions *kubeoptions.BuiltInAuthenticationOptions
}
Authentication enables anonymous, client certificate, OIDC and request header authentication, following the same pattern as kcp's front-proxy.
Its OIDC configuration must match kcp's: the access graph indexes RBAC subjects verbatim, so a username that differs by an issuer prefix resolves to no workspaces at all.
func NewAuthentication ¶
func NewAuthentication() *Authentication
NewAuthentication returns Authentication with the supported methods enabled.
func (*Authentication) AddFlags ¶
func (c *Authentication) AddFlags(fs *pflag.FlagSet)
AddFlags registers the --oidc-*, --authentication-config, --requestheader-* and --client-ca-file flags.
func (*Authentication) ApplyTo ¶
func (c *Authentication) ApplyTo( ctx context.Context, authenticationInfo *genericapiserver.AuthenticationInfo, servingInfo *genericapiserver.SecureServingInfo, ) error
ApplyTo builds the union authenticator and advertises the client and requestheader CAs on the serving side.
BuiltInAuthenticationOptions.ApplyTo is intentionally not called: it expects kube-apiserver infrastructure this component does not have.
func (*Authentication) OIDCEnabled ¶
func (c *Authentication) OIDCEnabled() bool
OIDCEnabled reports whether a JWT authenticator is configured.
func (*Authentication) RequestHeaderEnabled ¶
func (c *Authentication) RequestHeaderEnabled() bool
RequestHeaderEnabled reports whether identity headers from a trusted proxy are accepted.
func (*Authentication) Validate ¶
func (c *Authentication) Validate() []error
Validate reports configuration errors in the enabled methods.
type Options ¶
type Options struct {
// SecureServing configures TLS serving (bind address, port,
// serving certs). The VW must serve TLS: behind kcp's front-proxy
// the proxy verifies the VW's serving cert, and the VW verifies
// the proxy's client cert via the requestheader CA.
SecureServing *genericoptions.SecureServingOptions
// Authentication configures how callers are identified: a JWT
// authenticator (--authentication-config or the --oidc-* flags),
// request header identity forwarded by kcp's front-proxy, and
// client certificates. Its configuration must match kcp's, because
// the graph compares usernames verbatim against RBAC subjects —
// see authentication.go.
Authentication *Authentication
// Authorization is the virtual-workspace-framework authorizer setup:
// always-allow paths (health endpoints) plus per-VW authorizers.
Authorization *vwoptions.Authorization
// Kubeconfig is the path to the kubeconfig for the target kcp.
// Used by the RBAC provider's informers and as the base identity
// for impersonated per-workspace calls.
Kubeconfig string
// EndpointBase is the front-proxy URL prefix used to construct
// per-cluster endpoints in SCAR responses.
EndpointBase string
// APIExportEndpointSlice is the name of the APIExportEndpointSlice
// for the access VW's system APIExport. When set, the RBAC provider
// runs in multi-shard mode and only indexes workspaces bound to
// that APIExport.
APIExportEndpointSlice string
// WorkspacePath is the workspace the kubeconfig is retargeted to,
// e.g. "root:access:controllers". The APIExportEndpointSlice lookup
// happens in the workspace the kubeconfig points at; operator-minted
// admin kubeconfigs point at root, while the bootstrap assets live in
// the controllers workspace. Empty means use the kubeconfig as-is.
WorkspacePath string
// contains filtered or unexported fields
}
Options configures the access virtual workspace server.
func NewOptions ¶
func NewOptions() *Options
NewOptions returns options with defaults suitable for running behind kcp's front-proxy.