kms

package
v0.0.0-...-0efe4e0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: Apache-2.0 Imports: 6 Imported by: 1

Documentation

Index

Constants

This section is empty.

Variables

View Source
var SchemeGroupVersion = schema.GroupVersion{Group: "encryption.operator.openshift.io", Version: "v1"}

SchemeGroupVersion identifies the stored configuration; it is not a served API.

Functions

func AddToScheme

func AddToScheme(scheme *runtime.Scheme) error

Types

type EncryptionStatusProvider

type EncryptionStatusProvider interface {
	GetKMSEncryptionStatus(ctx context.Context) (*operatorv1.KMSEncryptionStatus, error)

	// ApplyKMSEncryptionStatus uses Server-Side Apply. Each caller owns only
	// the fields it explicitly sets, identified by fieldManager.
	ApplyKMSEncryptionStatus(ctx context.Context, fieldManager string, status *applyoperatorv1.KMSEncryptionStatusApplyConfiguration) error

	// UpdateKMSEncryptionStatus reads the current status, applies the mutation,
	// and writes it back. Implementations must retry on conflict (409).
	//
	// Note: use this instead of ApplyKMSEncryptionStatus when the controller is
	// the sole owner of a field. Apply requires re-sending every owned field on
	// every sync, omitting one causes the server to remove it, which is
	// cumbersome for a controller that only writes a field once.
	UpdateKMSEncryptionStatus(ctx context.Context, mutate func(*operatorv1.KMSEncryptionStatus)) error
}

EncryptionStatusProvider reads and writes the KMSEncryptionStatus sub-field of an operator CR. Get and Apply are safe for concurrent callers.

type KMSPluginConfig

type KMSPluginConfig struct {
	metav1.TypeMeta `json:",inline"`
	Type            KMSProviderType      `json:"type"`
	Vault           VaultKMSPluginConfig `json:"vault,omitempty,omitzero"`
}

KMSPluginConfig holds resolved plugin configuration. Remove this type when the encryption lifecycle uses unstructured configuration.

func (*KMSPluginConfig) DeepCopy

func (in *KMSPluginConfig) DeepCopy() *KMSPluginConfig

func (*KMSPluginConfig) DeepCopyObject

func (in *KMSPluginConfig) DeepCopyObject() runtime.Object

type KMSProviderType

type KMSProviderType string
const (
	VaultKMSProvider KMSProviderType = "Vault"
)

type VaultAppRoleAuthentication

type VaultAppRoleAuthentication struct {
	Secret VaultSecretReference `json:"secret,omitzero"`
}

type VaultAuthentication

type VaultAuthentication struct {
	Type    VaultAuthenticationType    `json:"type,omitempty"`
	AppRole VaultAppRoleAuthentication `json:"appRole,omitzero"`
}

type VaultAuthenticationType

type VaultAuthenticationType string
const (
	VaultAuthenticationTypeAppRole VaultAuthenticationType = "AppRole"
)

type VaultConfigMapReference

type VaultConfigMapReference struct {
	Name string `json:"name,omitempty"`
}

type VaultKMSPluginConfig

type VaultKMSPluginConfig struct {
	KMSPluginImage string `json:"kmsPluginImage,omitempty"`
	VaultAddress   string `json:"vaultAddress,omitempty"`

	VaultNamespace     string `json:"vaultNamespace,omitempty"`
	VaultAuthNamespace string `json:"vaultAuthNamespace,omitempty"`

	TLS            VaultTLSConfig      `json:"tls,omitzero"`
	Authentication VaultAuthentication `json:"authentication,omitzero"`

	VaultKeyPath string `json:"vaultKeyPath,omitempty"`
}

func (*VaultKMSPluginConfig) DeepCopy

type VaultSecretReference

type VaultSecretReference struct {
	Name string `json:"name,omitempty"`
}

type VaultTLSConfig

type VaultTLSConfig struct {
	CABundle   VaultConfigMapReference `json:"caBundle,omitzero"`
	ServerName string                  `json:"serverName,omitempty"`
}

Directories

Path Synopsis

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL