controller

package
v0.0.0-...-a06bb16 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: MIT Imports: 49 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// ProjectIDLabel and ProjectIDAnnotationFallback is where a team namespace
	// records which Google project it maps to.
	ProjectIDLabel              = "google-cloud-project"
	ProjectIDAnnotationFallback = "cnrm.cloud.google.com/project-id"
)
View Source
const ConditionReasonUnknown = "Unknown"

Variables

This section is empty.

Functions

This section is empty.

Types

type OpenSearchPreparedData

type OpenSearchPreparedData struct{}

OpenSearchPreparedData contains data prepared during the Prepare phase

type OpenSearchReconciler

type OpenSearchReconciler struct {
	Aiven  config.Aiven
	Tenant config.Tenant

	Recorder events.Recorder
	Scheme   *runtime.Scheme
}

OpenSearchReconciler reconciles an OpenSearch object

func (*OpenSearchReconciler) AdditionalTypes

func (r *OpenSearchReconciler) AdditionalTypes() []client.Object

func (*OpenSearchReconciler) Delete

func (*OpenSearchReconciler) FinalizerName

func (r *OpenSearchReconciler) FinalizerName() string

func (*OpenSearchReconciler) Name

func (r *OpenSearchReconciler) Name() string

func (*OpenSearchReconciler) New

func (*OpenSearchReconciler) OwnedTypes

func (r *OpenSearchReconciler) OwnedTypes() []reconciler.OwnedType

func (*OpenSearchReconciler) Prepare

func (*OpenSearchReconciler) Update

type PostgresAccessPreparedData

type PostgresAccessPreparedData struct {
	Branch         *v1.PostgresBranch         `yaml:"branch"`
	Cluster        *cnpgv1.Cluster            `yaml:"-"`
	Password       string                     `yaml:"-"`
	Role           *cnpgv1.DatabaseRole       `yaml:"-"`
	Token          string                     `yaml:"-"`
	TokenPersisted bool                       `yaml:"-"`
	RelayAccess    *unstructured.Unstructured `yaml:"-"`
	Expired        bool                       `yaml:"-"`
}

type PostgresAccessReconciler

type PostgresAccessReconciler struct {
	Recorder events.Recorder
	Scheme   *runtime.Scheme
}

PostgresAccessReconciler establishes the durable database identity behind a personal access. Session credentials, privileges and transport are added by later PostgresAccess reconciliation steps.

func (*PostgresAccessReconciler) AdditionalTypes

func (r *PostgresAccessReconciler) AdditionalTypes() []client.Object

func (*PostgresAccessReconciler) Indexes

func (r *PostgresAccessReconciler) Indexes() []reconciler.Index

func (*PostgresAccessReconciler) Name

func (r *PostgresAccessReconciler) Name() string

func (*PostgresAccessReconciler) New

func (*PostgresAccessReconciler) OwnedTypes

func (r *PostgresAccessReconciler) OwnedTypes() []reconciler.OwnedType

PostgresAccess owns its declarative access resources. The DatabaseRole uses Retain so CNPG preserves the PostgreSQL role and objects it owns after the access and DatabaseRole CR are deleted.

func (*PostgresAccessReconciler) Prepare

func (*PostgresAccessReconciler) RelationshipWatches

func (r *PostgresAccessReconciler) RelationshipWatches() []reconciler.RelationshipWatch

func (*PostgresAccessReconciler) Update

type PostgresBindingPreparedData

type PostgresBindingPreparedData struct {
	Branch   string `yaml:"branch"`
	Snapshot *bindingSnapshot
}

PostgresBindingPreparedData contains the selected branch and, when all CNPG source material is present, an internally consistent credential snapshot.

type PostgresBindingReconciler

type PostgresBindingReconciler struct {
	Recorder events.Recorder
	Scheme   *runtime.Scheme
}

PostgresBindingReconciler reconciles a nais.io/v1 PostgresBinding into a CloudNativePG DatabaseRole with an operator-issued client certificate, a connection Secret, and NetworkPolicies that open the path to the connection pooler.

func (*PostgresBindingReconciler) AdditionalTypes

func (r *PostgresBindingReconciler) AdditionalTypes() []client.Object

func (*PostgresBindingReconciler) Delete

Delete relies on ownerReference garbage collection. Everything a binding creates lives in the binding's own namespace, so there is nothing to clean up by hand.

This is destructive by design: read and readwrite DatabaseRoles carry databaseRoleReclaimPolicy: delete, so removing a binding runs DROP ROLE and revokes that workload's access immediately. That is the intent — a binding is the grant, so withdrawing it must withdraw the access.

Admin bindings retain the durable owner role when their DatabaseRole is deleted, while CloudNativePG garbage-collects the client certificate.

DROP ROLE fails if the role still owns objects. Read and readwrite roles never create objects, so this does not bite today, but a future writable role that owns tables would need ownership reassigned before its binding can be deleted.

func (*PostgresBindingReconciler) Indexes

func (*PostgresBindingReconciler) Name

func (*PostgresBindingReconciler) New

func (*PostgresBindingReconciler) OwnedTypes

func (*PostgresBindingReconciler) Prepare

Prepare verifies that the referenced Postgres exists in the same namespace.

Bindings are namespace-local by design: the namespace is the team boundary, so resolving the Postgres by name in the binding's own namespace is what enforces that a team cannot bind to another team's database.

func (*PostgresBindingReconciler) RelationshipWatches

func (r *PostgresBindingReconciler) RelationshipWatches() []reconciler.RelationshipWatch

func (*PostgresBindingReconciler) Update

type PostgresBranchPreparedData

type PostgresBranchPreparedData struct {
	PostgresName        string          `yaml:"postgresName"`
	PostgresUID         types.UID       `yaml:"postgresUID"`
	PostgresSpec        v1.PostgresSpec `yaml:"postgresSpec"`
	TeamGoogleProjectID string          `yaml:"teamGoogleProjectID"`
	ActiveBranch        string          `yaml:"activeBranch,omitempty"`
	PostgresDeleting    bool            `yaml:"postgresDeleting,omitempty"`
	RecoverySource      *rccnpg.RecoverySource
	RecoverySourceReady bool
	RecoveryClusterUID  types.UID `yaml:"recoveryClusterUID,omitempty"`
	BlockingRecoveries  []string  `yaml:"blockingRecoveries,omitempty"`
}

type PostgresBranchReconciler

type PostgresBranchReconciler struct {
	Config   *config.Config
	Recorder events.Recorder
	Scheme   *runtime.Scheme
}

func (*PostgresBranchReconciler) AdditionalTypes

func (r *PostgresBranchReconciler) AdditionalTypes() []client.Object

func (*PostgresBranchReconciler) Delete

func (*PostgresBranchReconciler) Indexes

func (r *PostgresBranchReconciler) Indexes() []reconciler.Index

func (*PostgresBranchReconciler) Name

func (r *PostgresBranchReconciler) Name() string

func (*PostgresBranchReconciler) New

func (*PostgresBranchReconciler) OwnedTypes

func (r *PostgresBranchReconciler) OwnedTypes() []reconciler.OwnedType

func (*PostgresBranchReconciler) Prepare

func (*PostgresBranchReconciler) RelationshipWatches

func (r *PostgresBranchReconciler) RelationshipWatches() []reconciler.RelationshipWatch

func (*PostgresBranchReconciler) Update

type PostgresPreparedData

type PostgresPreparedData struct {
	RequestedBranch string `yaml:"requestedBranch,omitempty"`
	RequestedReady  bool   `yaml:"requestedReady,omitempty"`
}

PostgresPreparedData contains data prepared during the Prepare phase.

type PostgresReconciler

type PostgresReconciler struct {
	Config   *config.Config
	Recorder events.Recorder
	Scheme   *runtime.Scheme
}

PostgresReconciler reconciles a nais.io/v1 Postgres object into logical resources. Physical CNPG resources are owned by PostgresBranch.

func (*PostgresReconciler) AdditionalTypes

func (r *PostgresReconciler) AdditionalTypes() []client.Object

func (*PostgresReconciler) Delete

func (*PostgresReconciler) MetricsLabels

func (r *PostgresReconciler) MetricsLabels(obj *v1.Postgres) map[string]string

func (*PostgresReconciler) Name

func (r *PostgresReconciler) Name() string

func (*PostgresReconciler) New

func (r *PostgresReconciler) New() *v1.Postgres

func (*PostgresReconciler) OwnedTypes

func (r *PostgresReconciler) OwnedTypes() []reconciler.OwnedType

func (*PostgresReconciler) Prepare

func (*PostgresReconciler) Update

func (r *PostgresReconciler) Update(obj *v1.Postgres, prepared PostgresPreparedData, relatedObjects reconciler.RelatedObjects) ([]action.Action, ctrl.Result, error)

type ValkeyPreparedData

type ValkeyPreparedData struct{}

ValkeyPreparedData contains data prepared during the Prepare phase

type ValkeyReconciler

type ValkeyReconciler struct {
	Aiven  config.Aiven
	Tenant config.Tenant

	Recorder events.Recorder
	Scheme   *runtime.Scheme
}

ValkeyReconciler reconciles a Valkey object

func (*ValkeyReconciler) AdditionalTypes

func (r *ValkeyReconciler) AdditionalTypes() []client.Object

func (*ValkeyReconciler) Delete

func (*ValkeyReconciler) FinalizerName

func (r *ValkeyReconciler) FinalizerName() string

func (*ValkeyReconciler) Name

func (r *ValkeyReconciler) Name() string

func (*ValkeyReconciler) New

func (r *ValkeyReconciler) New() *v1.Valkey

func (*ValkeyReconciler) OwnedTypes

func (r *ValkeyReconciler) OwnedTypes() []reconciler.OwnedType

func (*ValkeyReconciler) Prepare

func (*ValkeyReconciler) Update

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL