Documentation
¶
Overview ¶
Package graph provides an in-memory RBAC permission map for kcp.
The graph is the shared seam between providers and the SCAR HTTP handler: providers (the kcp-native RBAC reconciler, an external/FGA integration, etc.) populate the graph with Grant/Revoke calls, and the handler reads from it via ClustersFor. Providers depend on this package; the SCAR handler depends on this package; nothing in this package depends on either of them.
The package deliberately has no kcp imports so it stays reusable by other consumers (admin tooling, FrontProxy optimisations, future Warrants/Scopes evaluators if those land).
Index ¶
- type AccessEndpointSlice
- type Graph
- func (g *Graph) ClustersFor(user string, groups []string) []AccessEndpointSlice
- func (g *Graph) Forget(cluster LogicalCluster)
- func (g *Graph) Grant(subject Subject, cluster LogicalCluster, endpoint string)
- func (g *Graph) Ready() bool
- func (g *Graph) Revoke(subject Subject, cluster LogicalCluster)
- func (g *Graph) SetEndpoint(cluster LogicalCluster, endpoint string)
- func (g *Graph) SetReady()
- func (g *Graph) Snapshot() Snapshot
- type LogicalCluster
- type Snapshot
- type Subject
- type SubjectKind
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type AccessEndpointSlice ¶
type AccessEndpointSlice struct {
// ClusterName is the LogicalCluster identifier.
ClusterName string `json:"clusterName"`
// Endpoint is the FrontProxy URL for this cluster.
Endpoint string `json:"endpoint"`
}
AccessEndpointSlice is a single (cluster name, FrontProxy endpoint) pair returned to a caller.
type Graph ¶
type Graph struct {
// contains filtered or unexported fields
}
Graph is an in-memory RBAC permission map.
func (*Graph) ClustersFor ¶
func (g *Graph) ClustersFor(user string, groups []string) []AccessEndpointSlice
ClustersFor returns the clusters that the given user, with the given group memberships, has access to, paired with each cluster's FrontProxy endpoint.
func (*Graph) Forget ¶
func (g *Graph) Forget(cluster LogicalCluster)
Forget removes a cluster entirely: every subject's access to it, and the cluster's recorded endpoint. Providers should call this when a cluster is deleted from the underlying source so stale endpoints don't accumulate.
func (*Graph) Grant ¶
func (g *Graph) Grant(subject Subject, cluster LogicalCluster, endpoint string)
Grant records that subject has access to cluster, reachable at the given endpoint URL.
func (*Graph) Ready ¶
Ready reports whether the graph has completed its initial sync and is ready to serve accurate queries.
func (*Graph) Revoke ¶
func (g *Graph) Revoke(subject Subject, cluster LogicalCluster)
Revoke removes subject's access to cluster. When no subject can reach the cluster any more, its endpoint is dropped too, so Snapshot does not accumulate entries for clusters nobody can see.
func (*Graph) SetEndpoint ¶
func (g *Graph) SetEndpoint(cluster LogicalCluster, endpoint string)
SetEndpoint updates the URL a cluster is reachable at without touching who can access it. Providers call this when a shard or front-proxy URL moves for a cluster whose bindings are unchanged; without it the graph would keep serving the old URL until the next subject change.
type LogicalCluster ¶
type LogicalCluster string
type Snapshot ¶
type Snapshot struct {
Ready bool `json:"ready"`
Subjects map[string][]string `json:"subjects"` // subject → cluster names
Clusters map[string]string `json:"clusters"` // cluster name → endpoint
}
Snapshot is a point-in-time view of the graph for diagnostics.
type Subject ¶
type Subject struct {
Kind SubjectKind
Name string
}
type SubjectKind ¶
type SubjectKind string
const ( SubjectKindUser SubjectKind = "User" SubjectKindGroup SubjectKind = "Group" )