rbacprovider

package
v0.0.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 20, 2026 License: Apache-2.0 Imports: 33 Imported by: 0

Documentation

Overview

Package rbacprovider implements the kcp-native RBAC AccessProvider.

The provider observes ClusterRoleBindings and RoleBindings across kcp shards and projects them onto the shared access graph: each binding contributes (Subject, LogicalCluster) edges, the graph sums them, and the SCAR HTTP handler reads from it.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Provider

type Provider struct {
	// EndpointBaseURL is the front-proxy URL prefix; a cluster's endpoint is
	// this plus the cluster name.
	EndpointBaseURL string

	// RestConfig must reach the kcp root shard in multi-shard mode, so the
	// apiexport virtual workspace is addressable.
	RestConfig *rest.Config

	// APIExportEndpointSlice names the slice the provider follows to discover
	// workspaces.
	APIExportEndpointSlice string
	// contains filtered or unexported fields
}

Provider is the kcp-native RBAC AccessProvider. It watches ClusterRoleBindings and RoleBindings and projects them onto the access graph, treating any binding as "view" — rule-level evaluation against (Cluster)Roles is not implemented.

Start picks a mode from the fields set: multi-shard when RestConfig and APIExportEndpointSlice are both set, single-shard with RestConfig alone, and a no-op stub when RestConfig is nil.

func New

func New(endpointBaseURL string) *Provider

New returns a configured Provider in stub mode.

func (*Provider) EngagedClusters

func (p *Provider) EngagedClusters() int

EngagedClusters returns how many logical clusters the provider is watching. Zero on a ready graph means discovery found nothing, which is distinct from finding clusters that hold no bindings.

func (*Provider) Start

func (p *Provider) Start(ctx context.Context, g *graph.Graph) error

Start implements accessprovider.AccessProvider. It dispatches to one of three execution modes (multi-shard, single-shard, stub).

type Translator

type Translator struct {
	// contains filtered or unexported fields
}

Translator turns RBAC binding events into graph mutations.

func NewTranslator

func NewTranslator(g *graph.Graph) *Translator

NewTranslator returns a Translator that will emit Grant/Revoke calls on g.

func (*Translator) ApplyClusterRoleBinding

func (t *Translator) ApplyClusterRoleBinding(crb *rbacv1.ClusterRoleBinding, cluster graph.LogicalCluster, endpoint string)

ApplyClusterRoleBinding records the effect of a ClusterRoleBinding observed in the given logical cluster, addressable at endpoint.

func (*Translator) ApplyRoleBinding

func (t *Translator) ApplyRoleBinding(rb *rbacv1.RoleBinding, cluster graph.LogicalCluster, endpoint string)

ApplyRoleBinding is the namespaced analogue of ApplyClusterRoleBinding.

func (*Translator) ForgetCluster

func (t *Translator) ForgetCluster(cluster graph.LogicalCluster)

ForgetCluster removes every binding observed in the given cluster and clears the cluster's endpoint from the graph. Used when a workspace itself is deleted.

func (*Translator) RemoveClusterRoleBinding

func (t *Translator) RemoveClusterRoleBinding(name string, cluster graph.LogicalCluster)

RemoveClusterRoleBinding undoes a previously-applied CRB: every (subject, cluster) edge it contributed loses one reference, and any edge whose ref count reaches zero is Revoked on the graph.

func (*Translator) RemoveRoleBinding

func (t *Translator) RemoveRoleBinding(namespace, name string, cluster graph.LogicalCluster)

RemoveRoleBinding is the namespaced analogue of RemoveClusterRoleBinding.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL