server

package
v0.0.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 10, 2026 License: Apache-2.0 Imports: 29 Imported by: 0

Documentation

Overview

Package server wires the Access Virtual Workspace binary together: the shared access graph, the RBAC provider that populates it, and a virtual-workspace root apiserver (kcp virtual-workspace-framework) serving the access virtual workspace at /services/access behind kcp's front-proxy.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Run

func Run(ctx context.Context, o *Options) error

Run starts the provider and serves the Access virtual workspace until ctx is cancelled.

Types

type Authentication

type Authentication struct {
	BuiltInOptions *kubeoptions.BuiltInAuthenticationOptions
}

Authentication enables anonymous, client certificate, OIDC and request header authentication, following the same pattern as kcp's front-proxy.

Its OIDC configuration must match kcp's: the access graph indexes RBAC subjects verbatim, so a username that differs by an issuer prefix resolves to no workspaces at all.

func NewAuthentication

func NewAuthentication() *Authentication

NewAuthentication returns Authentication with the supported methods enabled.

func (*Authentication) AddFlags

func (c *Authentication) AddFlags(fs *pflag.FlagSet)

AddFlags registers the --oidc-*, --authentication-config, --requestheader-* and --client-ca-file flags.

func (*Authentication) ApplyTo

func (c *Authentication) ApplyTo(
	ctx context.Context,
	authenticationInfo *genericapiserver.AuthenticationInfo,
	servingInfo *genericapiserver.SecureServingInfo,
) error

ApplyTo builds the union authenticator and advertises the client and requestheader CAs on the serving side.

BuiltInAuthenticationOptions.ApplyTo is intentionally not called: it expects kube-apiserver infrastructure this component does not have.

func (*Authentication) OIDCEnabled

func (c *Authentication) OIDCEnabled() bool

OIDCEnabled reports whether a JWT authenticator is configured.

func (*Authentication) RequestHeaderEnabled

func (c *Authentication) RequestHeaderEnabled() bool

RequestHeaderEnabled reports whether identity headers from a trusted proxy are accepted.

func (*Authentication) Validate

func (c *Authentication) Validate() []error

Validate reports configuration errors in the enabled methods.

type Options

type Options struct {
	// SecureServing configures TLS serving (bind address, port,
	// serving certs). The VW must serve TLS: behind kcp's front-proxy
	// the proxy verifies the VW's serving cert, and the VW verifies
	// the proxy's client cert via the requestheader CA.
	SecureServing *genericoptions.SecureServingOptions

	// Authentication configures how callers are identified: a JWT
	// authenticator (--authentication-config or the --oidc-* flags),
	// request header identity forwarded by kcp's front-proxy, and
	// client certificates. Its configuration must match kcp's, because
	// the graph compares usernames verbatim against RBAC subjects —
	// see authentication.go.
	Authentication *Authentication

	// Authorization is the virtual-workspace-framework authorizer setup:
	// always-allow paths (health endpoints) plus per-VW authorizers.
	Authorization *vwoptions.Authorization

	// Kubeconfig is the path to the kubeconfig for the target kcp.
	// Used by the RBAC provider's informers and as the base identity
	// for impersonated per-workspace calls.
	Kubeconfig string

	// EndpointBase is the front-proxy URL prefix used to construct
	// per-cluster endpoints in SCAR responses.
	EndpointBase string

	// APIExportEndpointSlice is the name of the APIExportEndpointSlice
	// for the access VW's system APIExport. When set, the RBAC provider
	// runs in multi-shard mode and only indexes workspaces bound to
	// that APIExport.
	APIExportEndpointSlice string

	// WorkspacePath is the workspace the kubeconfig is retargeted to,
	// e.g. "root:access:controllers". The APIExportEndpointSlice lookup
	// happens in the workspace the kubeconfig points at; operator-minted
	// admin kubeconfigs point at root, while the bootstrap assets live in
	// the controllers workspace. Empty means use the kubeconfig as-is.
	WorkspacePath string
}

Options configures the access virtual workspace server.

func NewOptions

func NewOptions() *Options

NewOptions returns options with defaults suitable for running behind kcp's front-proxy.

func (*Options) AddFlags

func (o *Options) AddFlags(fs *pflag.FlagSet)

AddFlags registers all flags on the given flag set.

func (*Options) Complete

func (o *Options) Complete() error

Complete fills in derived defaults.

func (*Options) Validate

func (o *Options) Validate() error

Validate checks flag consistency, reporting every problem it finds rather than only the first.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL