opensearch

package
v0.4.21 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: May 4, 2026 License: Apache-2.0 Imports: 16 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func DefaultIndexMapping

func DefaultIndexMapping(semanticFields []string, semanticModelID string) (string, error)

DefaultIndexMapping returns the default OpenSearch index mapping for workspace and resource documents. - payload_raw is stored but not indexed (enabled=false). - payload_text stores the full serialized object for full-text search.

Types

type Client

type Client struct {
	// contains filtered or unexported fields
}

Client wraps the OpenSearch client with convenience methods

func NewClient

func NewClient(cfg Config) (*Client, error)

NewClient creates a new OpenSearch client

func NewClientFromEnv

func NewClientFromEnv(cfg *config.Config) (*Client, error)

NewClientFromEnv creates a new OpenSearch client using environment variables OPENSEARCH_URL, OPENSEARCH_USERNAME, OPENSEARCH_PASSWORD

func (*Client) CreateIndex

func (c *Client) CreateIndex(ctx context.Context, indexName string, numberOfShards, numberOfReplicas int32, mapping string) error

CreateIndex creates an index if it doesn't exist and applies initial settings.

func (*Client) DeleteDocument

func (c *Client) DeleteDocument(ctx context.Context, indexName, docID string) error

DeleteDocument deletes a document

func (*Client) DeleteIndex

func (c *Client) DeleteIndex(ctx context.Context, indexName string) error

DeleteIndex deletes an index

func (*Client) EnsureAliases

func (c *Client) EnsureAliases(ctx context.Context, indexName string, aliases []string) error

EnsureAliases ensures that all provided aliases exist for the given index.

func (*Client) GetIndexSettings

func (c *Client) GetIndexSettings(ctx context.Context, indexName string) (IndexSettings, error)

GetIndexSettings returns current number_of_shards and number_of_replicas for an index.

func (*Client) IndexDocument

func (c *Client) IndexDocument(ctx context.Context, indexName, docID string, document interface{}) error

IndexDocument indexes a document

func (*Client) IndexExists

func (c *Client) IndexExists(ctx context.Context, indexName string) (bool, error)

IndexExists checks if an index exists

func (*Client) Ping

func (c *Client) Ping(ctx context.Context) error

func (*Client) UpdateIndexReplicas

func (c *Client) UpdateIndexReplicas(ctx context.Context, indexName string, numberOfReplicas int32) error

UpdateIndexReplicas updates number_of_replicas for an existing index.

type Config

type Config struct {
	// URL is the OpenSearch server URL (e.g., https://localhost:9200)
	URL string
	// Username for basic auth
	Username string
	// Password for basic auth
	Password string
	// InsecureSkipVerify skips TLS certificate verification (for development)
	InsecureSkipVerify bool
}

type IndexSettings

type IndexSettings struct {
	NumberOfShards   int32
	NumberOfReplicas int32
}

IndexSettings contains index-level shard and replica settings.

type PermissionTuple

type PermissionTuple struct {
	// User is the subject of the permission (e.g., "user:alice" or "role:admin#assignee")
	User string `json:"user"`
	// Relation is the permission type (e.g., "member", "owner", "viewer")
	Relation string `json:"relation"`
	// Object is the target object (typically matches the document ID)
	Object string `json:"object"`
}

PermissionTuple represents an OpenFGA tuple embedded in the document This allows for permission-based filtering at search time

type ResourceDocument

type ResourceDocument struct {
	// Core resource identification
	ID        string `json:"id"`        // Unique document ID
	Kind      string `json:"kind"`      // Resource kind
	Name      string `json:"name"`      // Resource name
	Namespace string `json:"namespace"` // Resource namespace

	// API version info
	APIGroup   string `json:"api_group"`
	APIVersion string `json:"api_version"`

	// PM context
	ClusterName      string `json:"cluster_name"`
	WorkspacePath    string `json:"workspace_path"`
	OrganizationID   string `json:"organization_id,omitempty"`
	OrganizationName string `json:"organization_name,omitempty"`
	AccountID        string `json:"account_id,omitempty"`
	AccountName      string `json:"account_name,omitempty"`

	// FGAObject is the unique FGA object name for this document
	FGAObject string `json:"fga_object,omitempty"`

	// OpenFGA Permission Tuples for this resource
	Permissions []PermissionTuple `json:"permissions,omitempty"`

	// Resource metadata
	Labels      map[string]string `json:"labels,omitempty"`
	Annotations map[string]string `json:"annotations,omitempty"`

	// Resource spec and status (arbitrary nested maps from the unstructured object)
	Spec   map[string]interface{} `json:"spec,omitempty"`
	Status map[string]interface{} `json:"status,omitempty"`

	// CustomFields holds fields from the unstructured resource that are listed in
	// the SearchIndex's DefaultFields. These are propagated directly from the resource.
	CustomFields map[string]any `json:"custom_fields,omitempty"`

	// Timestamps
	CreatedAt time.Time `json:"created_at,omitempty"`
	UpdatedAt time.Time `json:"updated_at"`

	// Full raw object payload serialized as JSON, stored but not indexed.
	PayloadRawJSON string `json:"payload_raw_json,omitempty"`

	// Full serialized object payload for full-text search.
	PayloadText string `json:"payload_text,omitempty"`
}

ResourceDocument represents a generic Kubernetes resource indexed in OpenSearch

func NewResourceDocument

func NewResourceDocument(id, kind, name, namespace, clusterName, workspacePath string) *ResourceDocument

NewResourceDocument creates a new resource document with default values

func (*ResourceDocument) AddPermission

func (d *ResourceDocument) AddPermission(user, relation, object string)

AddPermission adds a permission tuple to the resource document

type WorkspaceDocument

type WorkspaceDocument struct {
	// Core workspace/account fields
	ID   string `json:"id"`   // Document ID (typically the cluster name)
	Name string `json:"name"` // Human-readable name
	Type string `json:"type"` // "workspace", "account", or "organization"

	// KCP-specific fields
	ClusterName string `json:"cluster_name"` // Logical cluster name
	Path        string `json:"path"`         // Full path in the KCP hierarchy

	// Organization context (for permission scoping)
	OrganizationID   string `json:"organization_id,omitempty"`
	OrganizationName string `json:"organization_name,omitempty"`

	// Account context (if applicable)
	AccountID   string `json:"account_id,omitempty"`
	AccountName string `json:"account_name,omitempty"`

	// FGAObject is the unique FGA object name for this document (e.g. "core_platform-mesh_io_account:ID/name")
	FGAObject string `json:"fga_object,omitempty"`

	// OpenFGA Permission Tuples for this resource
	Permissions []PermissionTuple `json:"permissions,omitempty"`

	// Timestamps
	CreatedAt time.Time `json:"created_at,omitempty"`
	UpdatedAt time.Time `json:"updated_at"`

	// Additional metadata
	Labels      map[string]string `json:"labels,omitempty"`
	Annotations map[string]string `json:"annotations,omitempty"`
}

WorkspaceDocument represents an indexed workspace/account in OpenSearch

func NewWorkspaceDocument

func NewWorkspaceDocument(id, name, workspaceType, clusterName, path string) *WorkspaceDocument

NewWorkspaceDocument creates a new workspace document with default values

func (*WorkspaceDocument) AddPermission

func (d *WorkspaceDocument) AddPermission(user, relation, object string)

AddPermission adds a permission tuple to the document

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL