Documentation
¶
Index ¶
- Variables
- func AddToScheme(scheme *runtime.Scheme) error
- type EncryptionStatusProvider
- type KMSPluginConfig
- type KMSProviderType
- type VaultAppRoleAuthentication
- type VaultAuthentication
- type VaultAuthenticationType
- type VaultConfigMapReference
- type VaultKMSPluginConfig
- type VaultSecretReference
- type VaultTLSConfig
Constants ¶
This section is empty.
Variables ¶
View Source
var SchemeGroupVersion = schema.GroupVersion{Group: "encryption.operator.openshift.io", Version: "v1"}
SchemeGroupVersion identifies the stored configuration; it is not a served API.
Functions ¶
func AddToScheme ¶
Types ¶
type EncryptionStatusProvider ¶
type EncryptionStatusProvider interface {
GetKMSEncryptionStatus(ctx context.Context) (*operatorv1.KMSEncryptionStatus, error)
// ApplyKMSEncryptionStatus uses Server-Side Apply. Each caller owns only
// the fields it explicitly sets, identified by fieldManager.
ApplyKMSEncryptionStatus(ctx context.Context, fieldManager string, status *applyoperatorv1.KMSEncryptionStatusApplyConfiguration) error
// UpdateKMSEncryptionStatus reads the current status, applies the mutation,
// and writes it back. Implementations must retry on conflict (409).
//
// Note: use this instead of ApplyKMSEncryptionStatus when the controller is
// the sole owner of a field. Apply requires re-sending every owned field on
// every sync, omitting one causes the server to remove it, which is
// cumbersome for a controller that only writes a field once.
UpdateKMSEncryptionStatus(ctx context.Context, mutate func(*operatorv1.KMSEncryptionStatus)) error
}
EncryptionStatusProvider reads and writes the KMSEncryptionStatus sub-field of an operator CR. Get and Apply are safe for concurrent callers.
type KMSPluginConfig ¶
type KMSPluginConfig struct {
metav1.TypeMeta `json:",inline"`
Type KMSProviderType `json:"type"`
Vault VaultKMSPluginConfig `json:"vault,omitempty,omitzero"`
}
KMSPluginConfig holds resolved plugin configuration. Remove this type when the encryption lifecycle uses unstructured configuration.
func (*KMSPluginConfig) DeepCopy ¶
func (in *KMSPluginConfig) DeepCopy() *KMSPluginConfig
func (*KMSPluginConfig) DeepCopyObject ¶
func (in *KMSPluginConfig) DeepCopyObject() runtime.Object
type KMSProviderType ¶
type KMSProviderType string
const (
VaultKMSProvider KMSProviderType = "Vault"
)
type VaultAppRoleAuthentication ¶
type VaultAppRoleAuthentication struct {
Secret VaultSecretReference `json:"secret,omitzero"`
}
type VaultAuthentication ¶
type VaultAuthentication struct {
Type VaultAuthenticationType `json:"type,omitempty"`
AppRole VaultAppRoleAuthentication `json:"appRole,omitzero"`
}
type VaultAuthenticationType ¶
type VaultAuthenticationType string
const (
VaultAuthenticationTypeAppRole VaultAuthenticationType = "AppRole"
)
type VaultConfigMapReference ¶
type VaultConfigMapReference struct {
Name string `json:"name,omitempty"`
}
type VaultKMSPluginConfig ¶
type VaultKMSPluginConfig struct {
KMSPluginImage string `json:"kmsPluginImage,omitempty"`
VaultAddress string `json:"vaultAddress,omitempty"`
VaultNamespace string `json:"vaultNamespace,omitempty"`
VaultAuthNamespace string `json:"vaultAuthNamespace,omitempty"`
TLS VaultTLSConfig `json:"tls,omitzero"`
Authentication VaultAuthentication `json:"authentication,omitzero"`
VaultKeyPath string `json:"vaultKeyPath,omitempty"`
}
func (*VaultKMSPluginConfig) DeepCopy ¶
func (in *VaultKMSPluginConfig) DeepCopy() *VaultKMSPluginConfig
type VaultSecretReference ¶
type VaultSecretReference struct {
Name string `json:"name,omitempty"`
}
type VaultTLSConfig ¶
type VaultTLSConfig struct {
CABundle VaultConfigMapReference `json:"caBundle,omitzero"`
ServerName string `json:"serverName,omitempty"`
}
Click to show internal directories.
Click to hide internal directories.