First draft for design
This commit is contained in:
@@ -0,0 +1,39 @@
|
||||
# Terdut operator
|
||||
|
||||
Aims to expose most config as CRD's, so end users can self-service over gitops.
|
||||
|
||||
See [DESIGN.md](./DESIGN.md) for the full design: CRD catalog and specs,
|
||||
reconciliation semantics, bootstrap/auth, Postgres integration, RBAC, and the
|
||||
relationship to `charts/terdut-server`. This README stays a short pitch; the
|
||||
open questions it used to carry are now resolved decisions there (§2).
|
||||
|
||||
## CRD's
|
||||
|
||||
### terdutServers
|
||||
Creates a server — Deployment, Service, database wiring, bootstrap, operator
|
||||
credentials. See DESIGN.md §4.1.
|
||||
|
||||
### terdutTeams
|
||||
- team name
|
||||
- oidc groups
|
||||
- `serverRef` — explicit reference to its `TerdutServer`, may be in a
|
||||
different namespace (one team owns the server, others self-service a
|
||||
team against it), gated by a `TerdutServerReferenceGrant` in the
|
||||
server's namespace (DESIGN.md §2, §4.2, §4.6)
|
||||
|
||||
### terdutServerReferenceGrants
|
||||
- lives in the `TerdutServer`'s namespace; lists which other namespaces'
|
||||
`TerdutTeam` objects may reference it (DESIGN.md §4.6)
|
||||
|
||||
### terdutEscalationrules
|
||||
- rule
|
||||
- `teamRef` — explicit reference to its `TerdutTeam` (DESIGN.md §2, §4.3)
|
||||
|
||||
### terdutDeadmansswitches
|
||||
- rule
|
||||
- `teamRef` (DESIGN.md §4.4)
|
||||
|
||||
### terdutAlertSources
|
||||
- `teamRef` (DESIGN.md §4.5)
|
||||
- URL/key are generated by the server at creation and surfaced only via a
|
||||
generated Secret, never set explicitly
|
||||
Reference in New Issue
Block a user