Documentation
¶
Overview ¶
Package rbacprovider implements the kcp-native RBAC AccessProvider.
The provider observes ClusterRoleBindings and RoleBindings across kcp shards and projects them onto the shared access graph: each binding contributes (Subject, LogicalCluster) edges, the graph sums them, and the SCAR HTTP handler reads from it.
Index ¶
- type Provider
- type Translator
- func (t *Translator) ApplyClusterRoleBinding(crb *rbacv1.ClusterRoleBinding, cluster graph.LogicalCluster, endpoint string)
- func (t *Translator) ApplyRoleBinding(rb *rbacv1.RoleBinding, cluster graph.LogicalCluster, endpoint string)
- func (t *Translator) ForgetCluster(cluster graph.LogicalCluster)
- func (t *Translator) RemoveClusterRoleBinding(name string, cluster graph.LogicalCluster)
- func (t *Translator) RemoveRoleBinding(namespace, name string, cluster graph.LogicalCluster)
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Provider ¶
type Provider struct {
// EndpointBaseURL is the front-proxy URL prefix; a cluster's endpoint is
// this plus the cluster name.
EndpointBaseURL string
// RestConfig must reach the kcp root shard in multi-shard mode, so the
// apiexport virtual workspace is addressable.
RestConfig *rest.Config
// APIExportEndpointSlice names the slice the provider follows to discover
// workspaces.
APIExportEndpointSlice string
// contains filtered or unexported fields
}
Provider is the kcp-native RBAC AccessProvider. It watches ClusterRoleBindings and RoleBindings and projects them onto the access graph, treating any binding as "view" — rule-level evaluation against (Cluster)Roles is not implemented.
Start picks a mode from the fields set: multi-shard when RestConfig and APIExportEndpointSlice are both set, single-shard with RestConfig alone, and a no-op stub when RestConfig is nil.
func (*Provider) EngagedClusters ¶
EngagedClusters returns how many logical clusters the provider is watching. Zero on a ready graph means discovery found nothing, which is distinct from finding clusters that hold no bindings.
type Translator ¶
type Translator struct {
// contains filtered or unexported fields
}
Translator turns RBAC binding events into graph mutations.
func NewTranslator ¶
func NewTranslator(g *graph.Graph) *Translator
NewTranslator returns a Translator that will emit Grant/Revoke calls on g.
func (*Translator) ApplyClusterRoleBinding ¶
func (t *Translator) ApplyClusterRoleBinding(crb *rbacv1.ClusterRoleBinding, cluster graph.LogicalCluster, endpoint string)
ApplyClusterRoleBinding records the effect of a ClusterRoleBinding observed in the given logical cluster, addressable at endpoint.
func (*Translator) ApplyRoleBinding ¶
func (t *Translator) ApplyRoleBinding(rb *rbacv1.RoleBinding, cluster graph.LogicalCluster, endpoint string)
ApplyRoleBinding is the namespaced analogue of ApplyClusterRoleBinding.
func (*Translator) ForgetCluster ¶
func (t *Translator) ForgetCluster(cluster graph.LogicalCluster)
ForgetCluster removes every binding observed in the given cluster and clears the cluster's endpoint from the graph. Used when a workspace itself is deleted.
func (*Translator) RemoveClusterRoleBinding ¶
func (t *Translator) RemoveClusterRoleBinding(name string, cluster graph.LogicalCluster)
RemoveClusterRoleBinding undoes a previously-applied CRB: every (subject, cluster) edge it contributed loses one reference, and any edge whose ref count reaches zero is Revoked on the graph.
func (*Translator) RemoveRoleBinding ¶
func (t *Translator) RemoveRoleBinding(namespace, name string, cluster graph.LogicalCluster)
RemoveRoleBinding is the namespaced analogue of RemoveClusterRoleBinding.