Documentation
¶
Index ¶
- func DefaultIndexMapping(semanticFields []string, semanticModelID string) (string, error)
- type Client
- func (c *Client) CreateIndex(ctx context.Context, indexName string, numberOfShards, numberOfReplicas int32, ...) (err error)
- func (c *Client) DeleteDocument(ctx context.Context, indexName, docID string) (err error)
- func (c *Client) DeleteIndex(ctx context.Context, indexName string) (err error)
- func (c *Client) EnsureAliases(ctx context.Context, indexName string, aliases []string) error
- func (c *Client) GetIndexSettings(ctx context.Context, indexName string) (IndexSettings, error)
- func (c *Client) IndexDocument(ctx context.Context, indexName, docID string, document interface{}) (err error)
- func (c *Client) IndexExists(ctx context.Context, indexName string) (bool, error)
- func (c *Client) Ping(ctx context.Context) error
- func (c *Client) UpdateIndexReplicas(ctx context.Context, indexName string, numberOfReplicas int32) (err error)
- type Config
- type IndexSettings
- type PermissionTuple
- type ResourceDocument
- type WorkspaceDocument
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func DefaultIndexMapping ¶
DefaultIndexMapping returns the default OpenSearch index mapping for workspace and resource documents. - payload_raw is stored but not indexed (enabled=false). - payload_text stores the full serialized object for full-text search.
Types ¶
type Client ¶
type Client struct {
// contains filtered or unexported fields
}
Client wraps the OpenSearch client with convenience methods
func NewClientFromEnv ¶
NewClientFromEnv creates a new OpenSearch client using environment variables OPENSEARCH_URL, OPENSEARCH_USERNAME, OPENSEARCH_PASSWORD
func (*Client) CreateIndex ¶
func (c *Client) CreateIndex(ctx context.Context, indexName string, numberOfShards, numberOfReplicas int32, mapping string) (err error)
CreateIndex creates an index if it doesn't exist and applies initial settings.
func (*Client) DeleteDocument ¶
DeleteDocument deletes a document
func (*Client) DeleteIndex ¶
DeleteIndex deletes an index
func (*Client) EnsureAliases ¶
EnsureAliases ensures that all provided aliases exist for the given index.
func (*Client) GetIndexSettings ¶
GetIndexSettings returns current number_of_shards and number_of_replicas for an index.
func (*Client) IndexDocument ¶
func (c *Client) IndexDocument(ctx context.Context, indexName, docID string, document interface{}) (err error)
IndexDocument indexes a document
func (*Client) IndexExists ¶
IndexExists checks if an index exists
type Config ¶
type Config struct {
// URL is the OpenSearch server URL (e.g., https://localhost:9200)
URL string
// Username for basic auth
Username string
// Password for basic auth
Password string
// InsecureSkipVerify skips TLS certificate verification (for development)
InsecureSkipVerify bool
}
type IndexSettings ¶
IndexSettings contains index-level shard and replica settings.
type PermissionTuple ¶
type PermissionTuple struct {
// User is the subject of the permission (e.g., "user:alice" or "role:admin#assignee")
User string `json:"user"`
// Relation is the permission type (e.g., "member", "owner", "viewer")
Relation string `json:"relation"`
// Object is the target object (typically matches the document ID)
Object string `json:"object"`
}
PermissionTuple represents an OpenFGA tuple embedded in the document This allows for permission-based filtering at search time
type ResourceDocument ¶
type ResourceDocument struct {
// Core resource identification
ID string `json:"id"` // Unique document ID
Kind string `json:"kind"` // Resource kind
Name string `json:"name"` // Resource name
Namespace string `json:"namespace"` // Resource namespace
// API version info
APIGroup string `json:"api_group"`
APIVersion string `json:"api_version"`
// PM context
ClusterName string `json:"cluster_name"`
WorkspacePath string `json:"workspace_path"`
OrganizationID string `json:"organization_id,omitempty"`
OrganizationName string `json:"organization_name,omitempty"`
AccountID string `json:"account_id,omitempty"`
AccountName string `json:"account_name,omitempty"`
// FGAObject is the unique FGA object name for this document
FGAObject string `json:"fga_object,omitempty"`
// OpenFGA Permission Tuples for this resource
Permissions []PermissionTuple `json:"permissions,omitempty"`
// Resource metadata
Labels map[string]string `json:"labels,omitempty"`
Annotations map[string]string `json:"annotations,omitempty"`
// Resource spec and status (arbitrary nested maps from the unstructured object)
Spec map[string]interface{} `json:"spec,omitempty"`
Status map[string]interface{} `json:"status,omitempty"`
// CustomFields holds fields from the unstructured resource that are listed in
// the SearchIndex's DefaultFields. These are propagated directly from the resource.
CustomFields map[string]any `json:"custom_fields,omitempty"`
// Timestamps
CreatedAt time.Time `json:"created_at,omitempty"`
UpdatedAt time.Time `json:"updated_at"`
// Full raw object payload serialized as JSON, stored but not indexed.
PayloadRawJSON string `json:"payload_raw_json,omitempty"`
// Full serialized object payload for full-text search.
PayloadText string `json:"payload_text,omitempty"`
}
ResourceDocument represents a generic Kubernetes resource indexed in OpenSearch
func NewResourceDocument ¶
func NewResourceDocument(id, kind, name, namespace, clusterName, workspacePath string) *ResourceDocument
NewResourceDocument creates a new resource document with default values
func (*ResourceDocument) AddPermission ¶
func (d *ResourceDocument) AddPermission(user, relation, object string)
AddPermission adds a permission tuple to the resource document
type WorkspaceDocument ¶
type WorkspaceDocument struct {
// Core workspace/account fields
ID string `json:"id"` // Document ID (typically the cluster name)
Name string `json:"name"` // Human-readable name
Type string `json:"type"` // "workspace", "account", or "organization"
// KCP-specific fields
ClusterName string `json:"cluster_name"` // Logical cluster name
Path string `json:"path"` // Full path in the KCP hierarchy
// Organization context (for permission scoping)
OrganizationID string `json:"organization_id,omitempty"`
OrganizationName string `json:"organization_name,omitempty"`
// Account context (if applicable)
AccountID string `json:"account_id,omitempty"`
AccountName string `json:"account_name,omitempty"`
// FGAObject is the unique FGA object name for this document (e.g. "core_platform-mesh_io_account:ID/name")
FGAObject string `json:"fga_object,omitempty"`
// OpenFGA Permission Tuples for this resource
Permissions []PermissionTuple `json:"permissions,omitempty"`
// Timestamps
CreatedAt time.Time `json:"created_at,omitempty"`
UpdatedAt time.Time `json:"updated_at"`
// Additional metadata
Labels map[string]string `json:"labels,omitempty"`
Annotations map[string]string `json:"annotations,omitempty"`
}
WorkspaceDocument represents an indexed workspace/account in OpenSearch
func NewWorkspaceDocument ¶
func NewWorkspaceDocument(id, name, workspaceType, clusterName, path string) *WorkspaceDocument
NewWorkspaceDocument creates a new workspace document with default values
func (*WorkspaceDocument) AddPermission ¶
func (d *WorkspaceDocument) AddPermission(user, relation, object string)
AddPermission adds a permission tuple to the document