rolebinding

package
v0.19.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 16, 2026 License: Apache-2.0 Imports: 7 Imported by: 0

Documentation

Overview

Package rolebinding provides a builder and resource for managing Kubernetes RoleBindings.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func ExtractInto added in v0.18.0

func ExtractInto[V any](b *Builder, cell *concepts.Data[V], fn func(rbacv1.RoleBinding) (V, error))

ExtractInto declares that this RoleBinding produces the value of cell. fn computes the value from a copy of the reconciled RoleBinding; the framework stores it in the cell and marks it present, immediately after the RoleBinding is applied or fetched. Extracting several values means several ExtractInto calls, one per cell. This is a package-level function because Go methods cannot introduce the extra type parameter V.

Types

type Builder

type Builder struct {
	// contains filtered or unexported fields
}

Builder is a configuration helper for creating and customizing a RoleBinding Resource.

It provides a fluent API for registering mutations and declared data extractions. Build() validates the configuration and returns an initialized Resource ready for use in a reconciliation loop.

func NewBuilder

func NewBuilder(rb *rbacv1.RoleBinding) *Builder

NewBuilder initializes a new Builder with the provided RoleBinding object.

The RoleBinding object serves as the desired base state. During reconciliation the Resource will make the cluster's state match this base, modified by any registered mutations.

roleRef must be set on the provided RoleBinding object. It is immutable after creation and is not modifiable via the mutation API.

The provided RoleBinding must have both Name and Namespace set, which is validated during the Build() call.

func (*Builder) Build

func (b *Builder) Build() (*Resource, error)

Build validates the configuration and returns the initialized Resource.

It returns an error if:

  • No RoleBinding object was provided.
  • The RoleBinding is missing a Name or Namespace.
  • The RoleRef is missing APIGroup, Kind, or Name.

func (*Builder) WithDataGuard added in v0.18.0

func (b *Builder) WithDataGuard(cells ...concepts.DataCell) *Builder

WithDataGuard declares that the RoleBinding reads the given data cells and must not be applied until every one of them is set. The framework generates the guard and its reason (waiting for data "<name>"), and component Build validates that a producer for each cell is registered earlier. Data guards are evaluated before any custom guard registered with WithGuard.

func (*Builder) WithGuard added in v0.4.0

func (b *Builder) WithGuard(guard func(rbacv1.RoleBinding) (concepts.GuardStatusWithReason, error)) *Builder

WithGuard registers a guard precondition that is evaluated before the RoleBinding is applied during reconciliation. If the guard returns Blocked, the RoleBinding and all resources registered after it are skipped until the guard clears. Passing nil clears any previously registered guard.

func (*Builder) WithMutation

func (b *Builder) WithMutation(ms ...Mutation) *Builder

WithMutation registers one or more mutations for the RoleBinding.

Mutations are applied sequentially during the Mutate() phase of reconciliation. A mutation with a nil Feature is applied unconditionally; one with a non-nil Feature is applied only when that feature is enabled.

func (*Builder) WithOptionalData added in v0.18.0

func (b *Builder) WithOptionalData(cells ...concepts.DataCell) *Builder

WithOptionalData declares that the RoleBinding reads the given data cells without gating on them. Component Build still validates that a producer is registered earlier, and the dependency stays visible to introspection. Consumers in this mode use Get and skip quietly when a cell is absent.

type Mutation

type Mutation feature.Mutation[*Mutator]

Mutation defines a mutation that is applied to a rolebinding Mutator only if its associated feature gate is enabled.

type Mutator

type Mutator struct {
	// contains filtered or unexported fields
}

Mutator is a high-level helper for modifying a Kubernetes RoleBinding.

It uses a "plan-and-apply" pattern: mutations are recorded first, then applied to the RoleBinding in a single controlled pass when Apply() is called.

The Mutator maintains feature boundaries: each feature's mutations are planned together and applied in the order the features were registered.

Mutator implements editors.ObjectMutator.

func NewMutator

func NewMutator(rb *rbacv1.RoleBinding) *Mutator

NewMutator creates a new Mutator for the given RoleBinding. The constructor creates the initial feature scope, so mutations can be registered immediately without an explicit call to NextFeature.

func (*Mutator) Apply

func (m *Mutator) Apply() error

Apply executes all recorded mutation intents on the underlying RoleBinding.

Execution order across all registered features:

  1. Metadata edits (in registration order within each feature)
  2. Subject edits (in registration order within each feature)

Features are applied in the order they were registered. Later features observe the RoleBinding as modified by all previous features.

func (*Mutator) EditObjectMetadata

func (m *Mutator) EditObjectMetadata(edit func(*editors.ObjectMetaEditor) error)

EditObjectMetadata records a mutation for the RoleBinding's own metadata.

Metadata edits are applied before subject edits within the same feature. A nil edit function is ignored.

func (*Mutator) EditSubjects

func (m *Mutator) EditSubjects(edit func(*editors.BindingSubjectsEditor) error)

EditSubjects records a mutation for the RoleBinding's subjects list via a BindingSubjectsEditor.

The editor provides structured operations (EnsureSubject, RemoveSubject) as well as Raw() for free-form access. Subject edits are applied after metadata edits within the same feature, in registration order.

A nil edit function is ignored.

func (*Mutator) NextFeature

func (m *Mutator) NextFeature()

NextFeature advances to a new feature planning scope. All subsequent mutation registrations will be grouped into this scope until NextFeature is called again.

The first scope is created automatically by NewMutator. This method is called by the framework between mutations to maintain per-feature ordering semantics.

type Resource

type Resource struct {
	// contains filtered or unexported fields
}

Resource is a high-level abstraction for managing a Kubernetes RoleBinding within a controller's reconciliation loop.

It implements the following component interfaces:

  • component.Resource: for basic identity and mutation behaviour.
  • concepts.Guardable: for conditional reconciliation based on a guard precondition.
  • concepts.DataExtractable: for exporting values after successful reconciliation.
  • concepts.ObservationRecorder: for surfacing live cluster state to declared data extractions on read-only reconciliation.

RoleBinding resources are static: they do not model convergence health, grace periods, or suspension.

func (*Resource) ConsumedData added in v0.18.0

func (r *Resource) ConsumedData() []concepts.DataConsumption

ConsumedData returns the RoleBinding's declared data reads. It satisfies concepts.DataConsumer for component topology validation and introspection.

func (*Resource) ExtractData

func (r *Resource) ExtractData() error

ExtractData executes all declared data extractions against a deep copy of the reconciled RoleBinding.

This is called by the framework after successful reconciliation, allowing the component to read generated or updated values from the RoleBinding.

func (*Resource) FiringSet added in v0.14.0

func (r *Resource) FiringSet() ([]string, error)

FiringSet returns the Names of registered mutations whose gate is enabled for the version the RoleBinding was built at. It satisfies concepts.MutationInspector.

func (*Resource) GuardStatus added in v0.4.0

func (r *Resource) GuardStatus() (concepts.GuardStatusWithReason, error)

GuardStatus evaluates the resource's guard precondition. If no guard was registered, the resource is unconditionally unblocked.

func (*Resource) Identity

func (r *Resource) Identity() string

Identity returns a unique identifier for the RoleBinding in the format "rbac.authorization.k8s.io/v1/RoleBinding/<namespace>/<name>".

func (*Resource) Mutate

func (r *Resource) Mutate(current client.Object) error

Mutate transforms the provided Kubernetes RoleBinding into the desired state.

Feature mutations are applied in registration order. This method is invoked by the framework during the Update phase of reconciliation.

func (*Resource) Object

func (r *Resource) Object() (client.Object, error)

Object returns a deep copy of the underlying Kubernetes RoleBinding object.

The returned object implements client.Object, making it compatible with controller-runtime's Client for Create, Update, and Patch operations.

func (*Resource) Preview added in v0.11.0

func (r *Resource) Preview() (client.Object, error)

Preview renders the RoleBinding as a client.Object with feature mutations applied, without modifying the resource's internal state. It satisfies the component's Previewable capability so the component can assemble a cluster-free preview.

Suspension mutations are not applied; the preview reflects content state only. Callers needing the concrete type can type-assert the returned object.

func (*Resource) ProducedData added in v0.18.0

func (r *Resource) ProducedData() []concepts.DataCell

ProducedData returns the cells this RoleBinding declares extractions into. It satisfies concepts.DataProducer for component topology validation and introspection.

func (*Resource) RecordObservation added in v0.9.1

func (r *Resource) RecordObservation(observed client.Object) error

RecordObservation stores the supplied object as the resource's most recently observed cluster state. The framework invokes this on read-only resources after fetching them so that declared data extractions observe the live object rather than the inert base used to construct the resource.

func (*Resource) RegisteredMutations added in v0.14.0

func (r *Resource) RegisteredMutations() []string

RegisteredMutations returns the deduplicated Names of every mutation registered on the RoleBinding, independent of version. It satisfies concepts.MutationInspector so the resource can be introspected for version-matrix golden generation.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL