konnect

package
v2.3.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 9, 2026 License: Apache-2.0 Imports: 70 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// KongCredentialTypeBasicAuth is the type of basic-auth credential, it's used
	// as the value for konghq.com/credential label.
	KongCredentialTypeBasicAuth = "basic-auth"
	// KongCredentialTypeAPIKey is the type of api-key credential, it's used
	// as the value for konghq.com/credential label.
	KongCredentialTypeAPIKey = "key-auth"
	// KongCredentialTypeJWT is the type of jwt-auth credential.
	// It's used as the values of konghq.com/credential label.
	KongCredentialTypeJWT = "jwt"
	// KongCredentialTypeACL is the type of Access Control Lists(ACLs) managed similar as credentials.
	// It's used as the value for konghq.com/credential label.
	KongCredentialTypeACL = "acl"
	// KongCredentialTypeHMAC is the type of HMAC credential, it's used
	// as the value for konghq.com/credential label.
	KongCredentialTypeHMAC = "hmac"
)
View Source
const (
	// CredentialSecretKeyNameAPIKeyKey is the credential secret key name for API key type.
	CredentialSecretKeyNameAPIKeyKey = "key"
	// CredentialSecretKeyNameACLGroupKey is the credential secret key name for ACL group type.
	CredentialSecretKeyNameACLGroupKey = "group"
	// CredentialSecretKeyNameJwtAlgorithmKey is the credential secret key name for JWT algorithm.
	CredentialSecretKeyNameJwtAlgorithmKey = "algorithm"
	// CredentialSecretKeyNameJwtKeyKey is the credential secret key name for JWT key.
	CredentialSecretKeyNameJwtKeyKey = "key"
	// CredentialSecretKeyNameJwtRSAPublicKeyKey is the credential secret key name for JWT RSA public key.
	CredentialSecretKeyNameJwtRSAPublicKeyKey = "rsa_public_key" //nolint:gosec
	// CredentialSecretKeyNameJwtSecretKey is the credentail secret ley name for JWT secret.
	CredentialSecretKeyNameJwtSecretKey = "secret"
	// CredentialSecretKeyNameHMACUsername is the credential secret key name for HMAC username type.
	CredentialSecretKeyNameHMACUsername = "username"
	// CredentialSecretKeyNameHMACSecret is the credential secret key name for HMAC secret type.
	CredentialSecretKeyNameHMACSecret = "secret"
)
View Source
const (
	// SecretTokenKey is the key used to store the token in the Secret.
	SecretTokenKey = "token"
	// SecretCredentialLabel is the label used to identify Secrets holding
	// KonnectAPIAuthConfiguration tokens.
	SecretCredentialLabel = "konghq.com/credential" //nolint:gosec
	// SecretCredentialLabelValueKonnect is the value of the label used to
	// identify Secrets holding KonnectAPIAuthConfiguration tokens.
	SecretCredentialLabelValueKonnect = "konnect"
)
View Source
const APIAuthInUseFinalizer = "konnect.konghq.com/konnectapiauth-in-use"

APIAuthInUseFinalizer is a finalizer added to KonnectAPIAuthConfiguration resources that are currently in use by other Konnect resources. This finalizer prevents the deletion of the authentication configuration until all dependent resources have been properly cleaned up or updated to use a different authentication method.

View Source
const (
	// CredentialTypeLabel is the label key for the credential type.
	CredentialTypeLabel = "konghq.com/credential" //nolint:gosec
)
View Source
const (
	// KonnectCleanupFinalizer is the finalizer that is added to the Konnect
	// entities when they are created in Konnect, and which is removed when
	// the CR and Konnect entity are deleted.
	KonnectCleanupFinalizer = "gateway.konghq.com/konnect-cleanup"
)
View Source
const (
	// SecretKonnectDataPlaneCertificateLabel is the label to mark that the secret is used as a Konnect DP certificate.
	// A secret must have the label to be watched by the KonnectExtension reconciler.
	SecretKonnectDataPlaneCertificateLabel = "konghq.com/konnect-dp-cert" //nolint:gosec
)

Variables

This section is empty.

Functions

func AIGatewayAgentReconciliationWatchOptions added in v2.3.0

func AIGatewayAgentReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

AIGatewayAgentReconciliationWatchOptions returns the watch options for the AIGatewayAgent.

func AIGatewayAuthStrategyReconciliationWatchOptions added in v2.3.0

func AIGatewayAuthStrategyReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

AIGatewayAuthStrategyReconciliationWatchOptions returns the watch options for the AIGatewayAuthStrategy.

func AIGatewayConsumerCredentialReconciliationWatchOptions added in v2.3.0

func AIGatewayConsumerCredentialReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

AIGatewayConsumerCredentialReconciliationWatchOptions returns the watch options for the AIGatewayConsumerCredential.

func AIGatewayConsumerGroupReconciliationWatchOptions added in v2.3.0

func AIGatewayConsumerGroupReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

AIGatewayConsumerGroupReconciliationWatchOptions returns the watch options for the AIGatewayConsumerGroup.

func AIGatewayConsumerReconciliationWatchOptions added in v2.3.0

func AIGatewayConsumerReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

AIGatewayConsumerReconciliationWatchOptions returns the watch options for the AIGatewayConsumer.

func AIGatewayDataPlaneCertificateReconciliationWatchOptions added in v2.3.0

func AIGatewayDataPlaneCertificateReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

AIGatewayDataPlaneCertificateReconciliationWatchOptions returns the watch options for the AIGatewayDataPlaneCertificate.

func AIGatewayMCPServerReconciliationWatchOptions added in v2.3.0

func AIGatewayMCPServerReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

AIGatewayMCPServerReconciliationWatchOptions returns the watch options for the AIGatewayMCPServer.

func AIGatewayModelProviderReconciliationWatchOptions added in v2.3.0

func AIGatewayModelProviderReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

AIGatewayModelProviderReconciliationWatchOptions returns the watch options for the AIGatewayModelProvider.

func AIGatewayModelReconciliationWatchOptions added in v2.3.0

func AIGatewayModelReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

AIGatewayModelReconciliationWatchOptions returns the watch options for the AIGatewayModel.

func AIGatewayPolicyReconciliationWatchOptions added in v2.3.0

func AIGatewayPolicyReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

AIGatewayPolicyReconciliationWatchOptions returns the watch options for the AIGatewayPolicy.

func EnsureFinalizerOnKonnectAPIAuthConfiguration added in v2.1.1

func EnsureFinalizerOnKonnectAPIAuthConfiguration(
	ctx context.Context,
	cl client.Client,
	apiAuth *konnectv1alpha1.KonnectAPIAuthConfiguration,
) (patched bool, err error)

EnsureFinalizerOnKonnectAPIAuthConfiguration ensures that the KonnectAPIAuthConfiguration has a finalizer if there are any resources referencing it, or removes the finalizer if there are no referencing resources.

It iterates through all types in KonnectAPIAuthReferencingTypeListsWithIndexes and checks if any resources of those types reference the given KonnectAPIAuthConfiguration. If at least one referencing resource is found, it adds the APIAuthInUseFinalizer to the KonnectAPIAuthConfiguration. If no referencing resources are found, it removes the finalizer.

Parameters:

  • ctx: The context for the operation
  • cl: The Kubernetes client used to list resources and patch the KonnectAPIAuthConfiguration
  • apiAuth: The KonnectAPIAuthConfiguration to ensure the finalizer on

Returns:

  • patched: true if the KonnectAPIAuthConfiguration was modified (finalizer added or removed), false otherwise
  • err: An error if the operation failed, nil otherwise

func EventGatewayBackendClusterReconciliationWatchOptions added in v2.2.0

func EventGatewayBackendClusterReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

EventGatewayBackendClusterReconciliationWatchOptions returns the watch options for the EventGatewayBackendCluster.

func EventGatewayDataPlaneCertificateReconciliationWatchOptions added in v2.2.0

func EventGatewayDataPlaneCertificateReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

EventGatewayDataPlaneCertificateReconciliationWatchOptions returns the watch options for the EventGatewayDataPlaneCertificate.

func EventGatewayListenerPolicyReconciliationWatchOptions added in v2.2.0

func EventGatewayListenerPolicyReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

EventGatewayListenerPolicyReconciliationWatchOptions returns the watch options for the EventGatewayListenerPolicy.

func EventGatewayListenerReconciliationWatchOptions added in v2.2.0

func EventGatewayListenerReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

EventGatewayListenerReconciliationWatchOptions returns the watch options for the EventGatewayListener.

func EventGatewaySchemaRegistryReconciliationWatchOptions added in v2.3.0

func EventGatewaySchemaRegistryReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

EventGatewaySchemaRegistryReconciliationWatchOptions returns the watch options for the EventGatewaySchemaRegistry.

func EventGatewayVirtualClusterConsumePolicyReconciliationWatchOptions added in v2.2.0

func EventGatewayVirtualClusterConsumePolicyReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

EventGatewayVirtualClusterConsumePolicyReconciliationWatchOptions returns the watch options for the EventGatewayVirtualClusterConsumePolicy.

func EventGatewayVirtualClusterPolicyReconciliationWatchOptions added in v2.2.0

func EventGatewayVirtualClusterPolicyReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

EventGatewayVirtualClusterPolicyReconciliationWatchOptions returns the watch options for the EventGatewayVirtualClusterPolicy.

func EventGatewayVirtualClusterProducePolicyReconciliationWatchOptions added in v2.2.0

func EventGatewayVirtualClusterProducePolicyReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

EventGatewayVirtualClusterProducePolicyReconciliationWatchOptions returns the watch options for the EventGatewayVirtualClusterProducePolicy.

func EventGatewayVirtualClusterReconciliationWatchOptions added in v2.2.0

func EventGatewayVirtualClusterReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

EventGatewayVirtualClusterReconciliationWatchOptions returns the watch options for the EventGatewayVirtualCluster.

func GetAPIAuthRefNN added in v2.1.7

GetAPIAuthRefNN returns the NamespacedName of the KonnectAPIAuthConfiguration referenced by the entity.

func GetTokenFromKonnectAPIAuthConfiguration added in v2.2.0

func GetTokenFromKonnectAPIAuthConfiguration(
	ctx context.Context, cl client.Client, apiAuth *konnectv1alpha1.KonnectAPIAuthConfiguration,
) (string, error)

GetTokenFromKonnectAPIAuthConfiguration returns the token from the secret reference or the token field.

func KongCACertificateReconciliationWatchOptions

func KongCACertificateReconciliationWatchOptions(cl client.Client) []func(*ctrl.Builder) *ctrl.Builder

KongCACertificateReconciliationWatchOptions returns the watch options for the KongCACertificate.

func KongCertificateReconciliationWatchOptions

func KongCertificateReconciliationWatchOptions(cl client.Client) []func(*ctrl.Builder) *ctrl.Builder

KongCertificateReconciliationWatchOptions returns the watch options for the KongCertificate.

func KongConsumerGroupReconciliationWatchOptions

func KongConsumerGroupReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

KongConsumerGroupReconciliationWatchOptions returns the watch options for the KongConsumerGroup.

func KongConsumerReconciliationWatchOptions

func KongConsumerReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

KongConsumerReconciliationWatchOptions returns the watch options for the KongConsumer.

func KongDataPlaneClientCertificateReconciliationWatchOptions

func KongDataPlaneClientCertificateReconciliationWatchOptions(cl client.Client) []func(*ctrl.Builder) *ctrl.Builder

KongDataPlaneClientCertificateReconciliationWatchOptions returns the watch options for the KongDataPlaneClientCertificate.

func KongKeyReconciliationWatchOptions

func KongKeyReconciliationWatchOptions(cl client.Client) []func(*ctrl.Builder) *ctrl.Builder

KongKeyReconciliationWatchOptions returns the watch options for the KongKey.

func KongKeySetReconciliationWatchOptions

func KongKeySetReconciliationWatchOptions(cl client.Client) []func(*ctrl.Builder) *ctrl.Builder

KongKeySetReconciliationWatchOptions returns the watch options for the KongKeySet.

func KongPluginBindingReconciliationWatchOptions

func KongPluginBindingReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

KongPluginBindingReconciliationWatchOptions returns the watch options for the KongPluginBinding.

func KongRouteReconciliationWatchOptions

func KongRouteReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

KongRouteReconciliationWatchOptions returns the watch options for the KongRoute.

func KongSNIReconciliationWatchOptions

func KongSNIReconciliationWatchOptions(cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

KongSNIReconciliationWatchOptions returns the watch options for the KongSNI.

func KongServiceReconciliationWatchOptions

func KongServiceReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

KongServiceReconciliationWatchOptions returns the watch options for the KongService.

func KongTargetReconciliationWatchOptions

func KongTargetReconciliationWatchOptions(cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

KongTargetReconciliationWatchOptions returns the watch options for the KongTarget.

func KongUpstreamReconciliationWatchOptions

func KongUpstreamReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

KongUpstreamReconciliationWatchOptions returns the watch options for the KongUpstream.

func KongVaultReconciliationWatchOptions

func KongVaultReconciliationWatchOptions(cl client.Client) []func(*ctrl.Builder) *ctrl.Builder

KongVaultReconciliationWatchOptions returns the watch options for KongVault.

func KonnectAIGatewayReconciliationWatchOptions added in v2.3.0

func KonnectAIGatewayReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

KonnectAIGatewayReconciliationWatchOptions returns the watch options for the KonnectAIGateway.

func KonnectCloudGatewayDataPlaneGroupConfigurationReconciliationWatchOptions

func KonnectCloudGatewayDataPlaneGroupConfigurationReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

KonnectCloudGatewayDataPlaneGroupConfigurationReconciliationWatchOptions returns the watch options for the KonnectCloudGatewayDataPlaneGroupConfiguration.

func KonnectCloudGatewayNetworkReconciliationWatchOptions

func KonnectCloudGatewayNetworkReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

KonnectCloudGatewayNetworkReconciliationWatchOptions returns the watch options for the KonnectCloudGatewayNetwork.

func KonnectCloudGatewayTransitGatewayWatchOptions

func KonnectCloudGatewayTransitGatewayWatchOptions(cl client.Client) []func(*ctrl.Builder) *ctrl.Builder

KonnectCloudGatewayTransitGatewayWatchOptions returns the watch options for KonnectCloudGatewayTransitGateway controller.

func KonnectConfigStoreReconciliationWatchOptions added in v2.3.0

func KonnectConfigStoreReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

KonnectConfigStoreReconciliationWatchOptions returns the watch options for the KonnectConfigStore.

func KonnectEventGatewayReconciliationWatchOptions added in v2.2.0

func KonnectEventGatewayReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

KonnectEventGatewayReconciliationWatchOptions returns the watch options for the KonnectEventGateway.

func KonnectGatewayControlPlaneReconciliationWatchOptions

func KonnectGatewayControlPlaneReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

KonnectGatewayControlPlaneReconciliationWatchOptions returns the watch options for the KonnectGatewayControlPlane.

func MCPServerReconciliationWatchOptions added in v2.2.0

func MCPServerReconciliationWatchOptions(cl client.Client) []func(*ctrl.Builder) *ctrl.Builder

MCPServerReconciliationWatchOptions returns the watch options for MCPServer.

func PortalCustomDomainReconciliationWatchOptions added in v2.2.0

func PortalCustomDomainReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

PortalCustomDomainReconciliationWatchOptions returns the watch options for the PortalCustomDomain.

func PortalCustomizationReconciliationWatchOptions added in v2.2.0

func PortalCustomizationReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

PortalCustomizationReconciliationWatchOptions returns the watch options for the PortalCustomization.

func PortalEmailConfigReconciliationWatchOptions added in v2.2.0

func PortalEmailConfigReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

PortalEmailConfigReconciliationWatchOptions returns the watch options for the PortalEmailConfig.

func PortalIPAllowListReconciliationWatchOptions added in v2.2.0

func PortalIPAllowListReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

PortalIPAllowListReconciliationWatchOptions returns the watch options for the PortalIPAllowList.

func PortalIdentityProviderRequestReconciliationWatchOptions added in v2.2.0

func PortalIdentityProviderRequestReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

PortalIdentityProviderRequestReconciliationWatchOptions returns the watch options for the PortalIdentityProviderRequest.

func PortalPageReconciliationWatchOptions added in v2.2.0

func PortalPageReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

PortalPageReconciliationWatchOptions returns the watch options for the PortalPage.

func PortalReconciliationWatchOptions added in v2.2.0

func PortalReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

PortalReconciliationWatchOptions returns the watch options for the Portal.

func PortalTeamReconciliationWatchOptions added in v2.2.0

func PortalTeamReconciliationWatchOptions(
	cl client.Client,
) []func(*ctrl.Builder) *ctrl.Builder

PortalTeamReconciliationWatchOptions returns the watch options for the PortalTeam.

func ReconciliationWatchOptionsForEntity

func ReconciliationWatchOptionsForEntity[
	T constraints.SupportedKonnectEntityType,
	TEnt constraints.EntityType[T],
](
	cl client.Client,
	ent TEnt,
) []func(*ctrl.Builder) *ctrl.Builder

ReconciliationWatchOptionsForEntity returns the watch options for the given Konnect entity type.

Types

type EntityWithControlPlaneRef

type EntityWithControlPlaneRef interface {
	SetControlPlaneID(string)
	GetControlPlaneID() string
}

EntityWithControlPlaneRef is an interface for entities that have a ControlPlaneRef.

type ForeignRelations

type ForeignRelations struct {
	Consumer      []configurationv1.KongConsumer
	ConsumerGroup []configurationv1beta1.KongConsumerGroup
	Route         []configurationv1alpha1.KongRoute
	Service       []configurationv1alpha1.KongService
}

ForeignRelations contains all the relations between Kong entities and KongPlugin.

func (*ForeignRelations) GetCombinations

func (relations *ForeignRelations) GetCombinations() []Rel

GetCombinations returns all possible combinations of relations.

NOTE: This is heavily based on the implementation in the Kong Ingress Controller: https://github.com/Kong/kubernetes-ingress-controller/blob/ee797b4e84bd176526af32ab6db54f16ee9c245b/internal/util/relations_test.go

TODO: https://github.com/kong/kong-operator/pull/659 The combinations created here should be reconsidered. Specifically the Service + Route combination which currently creates 2 separate relations targeting Service and Route independently. This most likely should create 2 relations targeting Service and Service+Route.

func (*ForeignRelations) GroupByControlPlane

func (relations *ForeignRelations) GroupByControlPlane(
	ctx context.Context,
	cl client.Client,
) (ForeignRelationsGroupedByControlPlane, error)

GroupByControlPlane groups all the entities by ControlPlane.

type ForeignRelationsGroupedByControlPlane

type ForeignRelationsGroupedByControlPlane map[types.NamespacedName]ForeignRelations

ForeignRelationsGroupedByControlPlane is a map of ForeignRelations grouped by ControlPlane.

func (ForeignRelationsGroupedByControlPlane) GetCombinations

GetCombinations returns all possible combinations of relations grouped by ControlPlane.

type KongCredentialSecretReconciler

type KongCredentialSecretReconciler struct {
	// contains filtered or unexported fields
}

KongCredentialSecretReconciler reconciles a KongPlugin object.

func NewKongCredentialSecretReconciler

func NewKongCredentialSecretReconciler(
	ctrlOptions controller.Options,
	loggingMode logging.Mode,
	client client.Client,
	scheme *runtime.Scheme,
) *KongCredentialSecretReconciler

NewKongCredentialSecretReconciler creates a new KongCredentialSecretReconciler.

func (*KongCredentialSecretReconciler) Reconcile

Reconcile reconciles a Secrets that are used as Consumers credentials.

func (*KongCredentialSecretReconciler) SetupWithManager

func (r *KongCredentialSecretReconciler) SetupWithManager(_ context.Context, mgr ctrl.Manager) error

SetupWithManager sets up the controller with the Manager.

type KongPluginBindingBuilder

type KongPluginBindingBuilder struct {
	// contains filtered or unexported fields
}

KongPluginBindingBuilder helps to build KongPluginBinding objects.

func NewKongPluginBindingBuilder

func NewKongPluginBindingBuilder() *KongPluginBindingBuilder

NewKongPluginBindingBuilder creates a new KongPluginBindingBuilder.

func (*KongPluginBindingBuilder) Build

Build returns the KongPluginBinding.

func (*KongPluginBindingBuilder) WithConsumerGroupTarget

func (b *KongPluginBindingBuilder) WithConsumerGroupTarget(cg string) *KongPluginBindingBuilder

WithConsumerGroupTarget sets the consumer group target of the KongPluginBinding.

func (*KongPluginBindingBuilder) WithConsumerTarget

func (b *KongPluginBindingBuilder) WithConsumerTarget(consumer string) *KongPluginBindingBuilder

WithConsumerTarget sets the consumer target of the KongPluginBinding.

func (*KongPluginBindingBuilder) WithControlPlaneRef

WithControlPlaneRef sets the control plane reference of the KongPluginBinding. NOTE: Users have to ensure that the ControlPlaneRef that's set here is the same across all the KongPluginBinding targets.

func (*KongPluginBindingBuilder) WithControlPlaneRefKonnectNamespaced

func (b *KongPluginBindingBuilder) WithControlPlaneRefKonnectNamespaced(name string) *KongPluginBindingBuilder

WithControlPlaneRefKonnectNamespaced sets the control plane reference of the KongPluginBinding. NOTE: Users have to ensure that the ControlPlaneRef that's set here is the same across all the KongPluginBinding targets.

func (*KongPluginBindingBuilder) WithGenerateName

func (b *KongPluginBindingBuilder) WithGenerateName(name string) *KongPluginBindingBuilder

WithGenerateName sets the generate name of the KongPluginBinding.

func (*KongPluginBindingBuilder) WithName

WithName sets the name of the KongPluginBinding.

func (*KongPluginBindingBuilder) WithNamespace

func (b *KongPluginBindingBuilder) WithNamespace(namespace string) *KongPluginBindingBuilder

WithNamespace sets the namespace of the KongPluginBinding.

func (*KongPluginBindingBuilder) WithOwnerReference

func (b *KongPluginBindingBuilder) WithOwnerReference(owner client.Object, scheme *runtime.Scheme) (*KongPluginBindingBuilder, error)

WithOwnerReference sets the owner reference of the KongPluginBinding.

func (*KongPluginBindingBuilder) WithPluginRefName added in v2.1.1

func (b *KongPluginBindingBuilder) WithPluginRefName(pluginName string) *KongPluginBindingBuilder

WithPluginRefName sets the plugin reference of the KongPluginBinding.

func (*KongPluginBindingBuilder) WithPluginRefNamespace added in v2.1.1

func (b *KongPluginBindingBuilder) WithPluginRefNamespace(pluginNamespace string) *KongPluginBindingBuilder

WithPluginRefNamespace sets the plugin reference namespace of the KongPluginBinding.

func (*KongPluginBindingBuilder) WithRouteTarget

func (b *KongPluginBindingBuilder) WithRouteTarget(routeName string) *KongPluginBindingBuilder

WithRouteTarget sets the route target of the KongPluginBinding.

func (*KongPluginBindingBuilder) WithScope

WithScope sets the scope of the KongPluginBinding.

func (*KongPluginBindingBuilder) WithServiceTarget

func (b *KongPluginBindingBuilder) WithServiceTarget(serviceName string) *KongPluginBindingBuilder

WithServiceTarget sets the service target of the KongPluginBinding.

type KongPluginReconciler

type KongPluginReconciler struct {
	// contains filtered or unexported fields
}

KongPluginReconciler reconciles a KongPlugin object.

func NewKongPluginReconciler

func NewKongPluginReconciler(
	ctrlOptions controller.Options,
	loggingMode logging.Mode,
	client client.Client,
) *KongPluginReconciler

NewKongPluginReconciler creates a new KongPluginReconciler.

func (*KongPluginReconciler) Reconcile

func (r *KongPluginReconciler) Reconcile(ctx context.Context, kongPlugin *configurationv1.KongPlugin) (ctrl.Result, error)

Reconcile reconciles a KongPlugin object. The purpose of this reconciler is to handle annotations on Kong entities objects that reference KongPlugin objects. As a result of such annotations, KongPluginBinding objects are created and managed by the controller.

func (*KongPluginReconciler) SetupWithManager

func (r *KongPluginReconciler) SetupWithManager(_ context.Context, mgr ctrl.Manager) error

SetupWithManager sets up the controller with the Manager.

type KonnectAPIAuthConfigurationReconciler

type KonnectAPIAuthConfigurationReconciler struct {
	// contains filtered or unexported fields
}

KonnectAPIAuthConfigurationReconciler reconciles a KonnectAPIAuthConfiguration object.

func NewKonnectAPIAuthConfigurationReconciler

func NewKonnectAPIAuthConfigurationReconciler(
	controllerOptions controller.Options,
	sdkFactory sdkops.SDKFactory,
	loggingMode logging.Mode,
	client client.Client,
) *KonnectAPIAuthConfigurationReconciler

NewKonnectAPIAuthConfigurationReconciler creates a new KonnectAPIAuthConfigurationReconciler.

func (*KonnectAPIAuthConfigurationReconciler) Reconcile

Reconcile reconciles a KonnectAPIAuthConfiguration object.

func (*KonnectAPIAuthConfigurationReconciler) SetupWithManager

SetupWithManager sets up the controller with the Manager.

type KonnectEntityPluginBindingFinalizerReconciler

type KonnectEntityPluginBindingFinalizerReconciler[
	T constraints.SupportedKonnectEntityPluginReferenceableType,
	TEnt constraints.EntityType[T],
] struct {
	ControllerOptions controller.Options
	LoggingMode       logging.Mode
	Client            client.Client
}

KonnectEntityPluginBindingFinalizerReconciler reconciles Konnect entities that may be referenced by KongPluginBinding. It uses the generic type constraints to constrain the supported types.

func NewKonnectEntityPluginReconciler

func NewKonnectEntityPluginReconciler[
	T constraints.SupportedKonnectEntityPluginReferenceableType,
	TEnt constraints.EntityType[T],
](
	controllerOptions controller.Options,
	loggingMode logging.Mode,
	client client.Client,
) *KonnectEntityPluginBindingFinalizerReconciler[T, TEnt]

NewKonnectEntityPluginReconciler returns a new KonnectEntityPluginReconciler for the given Konnect entity type.

func (*KonnectEntityPluginBindingFinalizerReconciler[T, TEnt]) Reconcile

func (r *KonnectEntityPluginBindingFinalizerReconciler[T, TEnt]) Reconcile(
	ctx context.Context, ent TEnt,
) (ctrl.Result, error)

Reconcile reconciles the Konnect entity that can be set as KongPluginBinding target. It reconciles only entities that are referenced by managed KongPluginBindings, i.e. those that are created by the controller out of konghq.com/plugins annotations.

Its purpose is to:

  • check if the entity is marked for deletion and mark KongPluginBindings that reference it.
  • add a finalizer to the entity if there are KongPluginBindings referencing it. This finalizer designates that this entity needs to have its KongPluginBindings removed upon deletion
  • remove the finalizer if all KongPluginBindings referencing it are removed.

func (*KonnectEntityPluginBindingFinalizerReconciler[T, TEnt]) SetupWithManager

func (r *KonnectEntityPluginBindingFinalizerReconciler[T, TEnt]) SetupWithManager(
	ctx context.Context, mgr ctrl.Manager,
) error

SetupWithManager sets up the controller with the given manager.

type KonnectEntityReconciler

type KonnectEntityReconciler[T constraints.SupportedKonnectEntityType, TEnt constraints.EntityType[T]] struct {
	ControllerOptions controller.Options
	Client            client.Client
	LoggingMode       logging.Mode
	SyncPeriod        time.Duration

	MetricRecorder metrics.Recorder
	// contains filtered or unexported fields
}

KonnectEntityReconciler reconciles a Konnect entities. It uses the generic type constraints to constrain the supported types.

func NewKonnectEntityReconciler

func NewKonnectEntityReconciler[
	T constraints.SupportedKonnectEntityType,
	TEnt constraints.EntityType[T],
](
	sdkFactory sdkops.SDKFactory,
	loggingMode logging.Mode,
	client client.Client,
	opts ...KonnectEntityReconcilerOption[T, TEnt],
) *KonnectEntityReconciler[T, TEnt]

NewKonnectEntityReconciler returns a new KonnectEntityReconciler for the given Konnect entity type.

func (*KonnectEntityReconciler[T, TEnt]) Reconcile

func (r *KonnectEntityReconciler[T, TEnt]) Reconcile(ctx context.Context, ent TEnt) (ctrl.Result, error)

Reconcile reconciles the given Konnect entity.

func (*KonnectEntityReconciler[T, TEnt]) SetupWithManager

func (r *KonnectEntityReconciler[T, TEnt]) SetupWithManager(ctx context.Context, mgr ctrl.Manager) error

SetupWithManager sets up the controller with the given manager.

type KonnectEntityReconcilerOption

type KonnectEntityReconcilerOption[
	T constraints.SupportedKonnectEntityType,
	TEnt constraints.EntityType[T],
] func(*KonnectEntityReconciler[T, TEnt])

KonnectEntityReconcilerOption is a functional option for the KonnectEntityReconciler.

func WithControllerOptions added in v2.1.1

func WithControllerOptions[T constraints.SupportedKonnectEntityType, TEnt constraints.EntityType[T]](
	controllerOptions controller.Options,
) KonnectEntityReconcilerOption[T, TEnt]

WithControllerOptions sets the controller options for the reconciler.

func WithKonnectEntitySyncPeriod

func WithKonnectEntitySyncPeriod[T constraints.SupportedKonnectEntityType, TEnt constraints.EntityType[T]](
	d time.Duration,
) KonnectEntityReconcilerOption[T, TEnt]

WithKonnectEntitySyncPeriod sets the sync period for the reconciler.

func WithMetricRecorder

func WithMetricRecorder[T constraints.SupportedKonnectEntityType, TEnt constraints.EntityType[T]](
	metricRecorder metrics.Recorder,
) KonnectEntityReconcilerOption[T, TEnt]

WithMetricRecorder sets the metric recorder to record metrics of Konnect entity operations of the reconciler.

type KonnectExtensionReconciler

type KonnectExtensionReconciler struct {
	client.Client

	ControllerOptions        controller.Options
	LoggingMode              logging.Mode
	SyncPeriod               time.Duration
	ClusterCASecretName      string
	ClusterCASecretNamespace string
	SecretLabelSelector      string
	CertTTL                  time.Duration
}

KonnectExtensionReconciler reconciles a KonnectExtension object.

func (*KonnectExtensionReconciler) Reconcile

Reconcile reconciles a KonnectExtension object.

func (*KonnectExtensionReconciler) SetupWithManager

func (r *KonnectExtensionReconciler) SetupWithManager(ctx context.Context, mgr ctrl.Manager) error

SetupWithManager sets up the controller with the Manager.

type KonnectSecretReferenceController added in v2.1.1

type KonnectSecretReferenceController struct {
	// contains filtered or unexported fields
}

KonnectSecretReferenceController reconciles Secret objects that are referenced by Konnect resources. It manages the SecretInUseFinalizer to prevent deletion of secrets while they are still referenced. by Konnect resources.

func NewKonnectSecretReferenceController added in v2.1.1

func NewKonnectSecretReferenceController(
	client client.Client,
	controllerOptions controller.Options,
	loggingMode logging.Mode,
) *KonnectSecretReferenceController

NewKonnectSecretReferenceController creates a new KonnectSecretReferenceController.

func (*KonnectSecretReferenceController) Reconcile added in v2.1.1

Reconcile reconciles a Secret object.

func (*KonnectSecretReferenceController) SetupWithManager added in v2.1.1

func (r *KonnectSecretReferenceController) SetupWithManager(ctx context.Context, mgr ctrl.Manager) error

SetupWithManager sets up the controller with the Manager.

type ReferencedKongCACertificateBelongsToWrongControlPlaneError added in v2.2.0

type ReferencedKongCACertificateBelongsToWrongControlPlaneError struct {
	Reference   types.NamespacedName
	CertCPID    string
	ServiceCPID string
}

ReferencedKongCACertificateBelongsToWrongControlPlaneError is returned when a referenced KongCACertificate belongs to a different ControlPlane.

func (ReferencedKongCACertificateBelongsToWrongControlPlaneError) Error added in v2.2.0

Error implements the error interface.

type ReferencedKongCACertificateDoesNotExistError added in v2.2.0

type ReferencedKongCACertificateDoesNotExistError struct {
	Reference types.NamespacedName
	Err       error
}

ReferencedKongCACertificateDoesNotExistError is an error type that is returned when a Konnect entity references a KongCACertificate which does not exist.

func (ReferencedKongCACertificateDoesNotExistError) Error added in v2.2.0

Error implements the error interface.

type ReferencedKongCertificateDoesNotExistError added in v2.2.0

type ReferencedKongCertificateDoesNotExistError struct {
	Reference types.NamespacedName
	Err       error
}

ReferencedKongCertificateDoesNotExistError is an error type that is returned when a Konnect entity references a Kong Certificate which does not exist.

func (ReferencedKongCertificateDoesNotExistError) Error added in v2.2.0

Error implements the error interface.

type ReferencedKongCertificateIsBeingDeletedError added in v2.2.0

type ReferencedKongCertificateIsBeingDeletedError struct {
	Reference         types.NamespacedName
	DeletionTimestamp time.Time
}

ReferencedKongCertificateIsBeingDeletedError is an error type that is returned when a Konnect entity references a Kong Certificate which is being deleted.

func (ReferencedKongCertificateIsBeingDeletedError) Error added in v2.2.0

Error implements the error interface.

type ReferencedKongConsumerDoesNotExistError added in v2.2.0

type ReferencedKongConsumerDoesNotExistError struct {
	Reference types.NamespacedName
	Err       error
}

ReferencedKongConsumerDoesNotExistError is an error type that is returned when the referenced KongConsumer does not exist.

func (ReferencedKongConsumerDoesNotExistError) Error added in v2.2.0

Error implements the error interface.

type ReferencedKongConsumerIsBeingDeletedError added in v2.2.0

type ReferencedKongConsumerIsBeingDeletedError struct {
	Reference         types.NamespacedName
	DeletionTimestamp time.Time
}

ReferencedKongConsumerIsBeingDeletedError is an error type that is returned when a Konnect entity references a Kong Consumer which is being deleted.

func (ReferencedKongConsumerIsBeingDeletedError) Error added in v2.2.0

Error implements the error interface.

type ReferencedKongKeySetDoesNotExistError added in v2.2.0

type ReferencedKongKeySetDoesNotExistError struct {
	Reference types.NamespacedName
	Err       error
}

ReferencedKongKeySetDoesNotExistError is an error type that is returned when a Konnect entity references a KongKeySet which does not exist.

func (ReferencedKongKeySetDoesNotExistError) Error added in v2.2.0

Error implements the error interface.

type ReferencedKongKeySetIsBeingDeletedError added in v2.2.0

type ReferencedKongKeySetIsBeingDeletedError struct {
	Reference         types.NamespacedName
	DeletionTimestamp time.Time
}

ReferencedKongKeySetIsBeingDeletedError is an error type that is returned when a Konnect entity references a KongKeySet which is being deleted.

func (ReferencedKongKeySetIsBeingDeletedError) Error added in v2.2.0

Error implements the error interface.

type ReferencedKongServiceIsBeingDeletedError added in v2.2.0

type ReferencedKongServiceIsBeingDeletedError struct {
	Reference types.NamespacedName
}

ReferencedKongServiceIsBeingDeletedError is an error type that is returned when a Konnect entity references a Kong Service which is being deleted.

func (ReferencedKongServiceIsBeingDeletedError) Error added in v2.2.0

Error implements the error interface.

type ReferencedKongUpstreamDoesNotExistError added in v2.2.0

type ReferencedKongUpstreamDoesNotExistError struct {
	Reference types.NamespacedName
	Err       error
}

ReferencedKongUpstreamDoesNotExistError is an error type that is returned when a Konnect entity references a Kong Upstream which does not exist.

func (ReferencedKongUpstreamDoesNotExistError) Error added in v2.2.0

Error implements the error interface.

type ReferencedKongUpstreamIsBeingDeletedError added in v2.2.0

type ReferencedKongUpstreamIsBeingDeletedError struct {
	Reference         types.NamespacedName
	DeletionTimestamp time.Time
}

ReferencedKongUpstreamIsBeingDeletedError is an error type that is returned when a Konnect entity references a Kong Upstream which is being deleted.

func (ReferencedKongUpstreamIsBeingDeletedError) Error added in v2.2.0

Error implements the error interface.

type ReferencedObjectDoesNotExistError added in v2.2.0

type ReferencedObjectDoesNotExistError struct {
	Reference types.NamespacedName
	Err       error
}

ReferencedObjectDoesNotExistError is an error type that is returned when a Konnect entity references a non existing object.

func (ReferencedObjectDoesNotExistError) Error added in v2.2.0

Error implements the error interface.

type ReferencedObjectIsBeingDeletedError added in v2.2.0

type ReferencedObjectIsBeingDeletedError struct {
	Reference         types.NamespacedName
	DeletionTimestamp time.Time
}

ReferencedObjectIsBeingDeletedError is an error type that is returned when a Konnect entity references an object which is being deleted.

func (ReferencedObjectIsBeingDeletedError) Error added in v2.2.0

Error implements the error interface.

type ReferencedObjectIsInvalidError added in v2.2.0

type ReferencedObjectIsInvalidError struct {
	Reference string
	Msg       string
}

ReferencedObjectIsInvalidError is an error type that is returned when the referenced object is invalid.

func (ReferencedObjectIsInvalidError) Error added in v2.2.0

Error implements the error interface.

type ReferencedSecretDoesNotExistError added in v2.2.0

type ReferencedSecretDoesNotExistError struct {
	Reference types.NamespacedName
	Err       error
}

ReferencedSecretDoesNotExistError is an error type that is returned when a Konnect entity references a Secret which does not exist.

func (ReferencedSecretDoesNotExistError) Error added in v2.2.0

Error implements the error interface.

type Rel

type Rel struct {
	Consumer, ConsumerGroup, Route, Service string
}

Rel represents a relation between Kong entities and KongPlugin.

type SecretInUseEnforceT added in v2.1.1

type SecretInUseEnforceT string

SecretInUseEnforceT is an enum type for enforcing or removing the secret-in-use finalizer.

const (
	// SecretInUseEnforceAdd enforces the secret-in-use finalizer.
	SecretInUseEnforceAdd SecretInUseEnforceT = "add"
	// SecretInUseEnforceRemove removes the secret-in-use finalizer.
	SecretInUseEnforceRemove SecretInUseEnforceT = "remove"
)

type UnsupportedGeneratedReferenceTypeError added in v2.2.0

type UnsupportedGeneratedReferenceTypeError struct {
	TypeName string
}

UnsupportedGeneratedReferenceTypeError is returned by generated reference handlers when they encounter a reference type that they do not support.

func (*UnsupportedGeneratedReferenceTypeError) Error added in v2.2.0

Error implements the error interface.

type WatchableEntityType added in v2.1.1

type WatchableEntityType interface {
	konnectv1alpha2.KonnectGatewayControlPlane |
		konnectv1alpha1.KonnectCloudGatewayNetwork |
		konnectv1alpha1.KonnectCloudGatewayDataPlaneGroupConfiguration |
		konnectv1alpha1.KonnectCloudGatewayTransitGateway |
		konnectv1alpha1.Portal |
		konnectv1alpha1.PortalPage |
		konnectv1alpha1.PortalCustomDomain |
		konnectv1alpha1.PortalCustomization |
		konnectv1alpha1.PortalEmailConfig |
		konnectv1alpha1.PortalIPAllowList |
		konnectv1alpha1.PortalTeam |
		konnectv1alpha1.PortalIdentityProviderRequest |
		konnectv1alpha1.KonnectAIGateway |
		konnectv1alpha1.KonnectConfigStore |
		aiconfigurationv1alpha1.AIGatewayAuthStrategy |
		aiconfigurationv1alpha1.AIGatewayModel |
		aiconfigurationv1alpha1.AIGatewayModelProvider |
		aiconfigurationv1alpha1.AIGatewayPolicy |
		aiconfigurationv1alpha1.AIGatewayAgent |
		aiconfigurationv1alpha1.AIGatewayConsumer |
		aiconfigurationv1alpha1.AIGatewayConsumerCredential |
		aiconfigurationv1alpha1.AIGatewayConsumerGroup |
		aiconfigurationv1alpha1.AIGatewayMCPServer |
		aiconfigurationv1alpha1.AIGatewayDataPlaneCertificate |
		konnectv1alpha1.KonnectEventGateway |
		configurationv1alpha1.EventGatewayBackendCluster |
		configurationv1alpha1.EventGatewayListener |
		configurationv1alpha1.EventGatewayListenerPolicy |
		configurationv1alpha1.EventGatewayVirtualCluster |
		configurationv1alpha1.EventGatewayVirtualClusterPolicy |
		configurationv1alpha1.EventGatewayVirtualClusterConsumePolicy |
		configurationv1alpha1.EventGatewayVirtualClusterProducePolicy |
		configurationv1alpha1.EventGatewayDataPlaneCertificate |
		configurationv1alpha1.EventGatewaySchemaRegistry |
		configurationv1alpha1.KongService |
		configurationv1alpha1.KongRoute |
		configurationv1.KongConsumer |
		configurationv1beta1.KongConsumerGroup |
		configurationv1alpha1.KongPluginBinding |
		configurationv1alpha1.KongCredentialBasicAuth |
		configurationv1alpha1.KongCredentialAPIKey |
		configurationv1alpha1.KongCredentialACL |
		configurationv1alpha1.KongCredentialJWT |
		configurationv1alpha1.KongCredentialHMAC |
		configurationv1alpha1.KongUpstream |
		configurationv1alpha1.KongCACertificate |
		configurationv1alpha1.KongCertificate |
		configurationv1alpha1.KongTarget |
		configurationv1alpha1.KongVault |
		configurationv1alpha1.KongKey |
		configurationv1alpha1.KongKeySet |
		configurationv1alpha1.KongSNI |
		configurationv1alpha1.KongDataPlaneClientCertificate |
		konnectv1alpha1.KonnectAPIAuthConfiguration

	GetTypeName() string
}

WatchableEntityType is a constraint that represents all Konnect-related entity types that can be watched.

Source Files

Directories

Path Synopsis
ops
sdk

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL