Both child CRDs resolve their own teamRef -> TerdutTeam.status via the new
shared resolveTeamAndClient helper (childref.go), never chaining up to
TerdutServer (DESIGN.md §5) -- TerdutTeam.status.serverEndpoint, added in
this same stage, is what makes that literally true.
TerdutEscalationRule: one PUT /api/teams/{id}/escalation per reconcile
(an upsert server-side, confirmed against source), resolving each "user"
target's username to a user_id via GET /api/users first and reporting
Ready: False, reason: UnknownUser if it doesn't resolve. No DELETE exists
for this resource, so its delete path PUTs an empty policy as the closest
available undo.
TerdutDeadmanSwitch: real create/update-in-place/delete, using
terdut-server v0.33.0's PUT (added specifically for this operator). No
unique-name constraint server-side, so idempotent-create here is
GET-list-and-match-by-name rather than adopt-on-409.
Extends tdclient with User/GetUserByUsername, the escalation request types
+ SetEscalation, and DeadmanSwitch + its CRUD methods. Also folds
ConditionTeamReady into the single shared ConditionReady constant, since
both were literally "Ready" and Stage 3 would otherwise have needed a
third same-valued constant.
internal/controller/terdutserver_controller_test.go's fakeTerdutServer
grows GET /api/users, PUT .../escalation, and the full dead man's switch
collection/item routes, replacing the old parseTeamPath/handleTeamByID
pair with a more general parseTeamSubPath/handleTeamSubPath dispatcher
that still covers every existing Stage 1/2 route unchanged.
make fmt lint test build all clean; envtest coverage for
internal/controller: 50.5% -> 71.7%.
This commit is contained in:
@@ -6,6 +6,8 @@ import (
|
||||
"fmt"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strconv"
|
||||
"strings"
|
||||
"sync"
|
||||
|
||||
. "github.com/onsi/ginkgo/v2"
|
||||
@@ -51,20 +53,54 @@ type fakeTerdutServer struct {
|
||||
teamNames map[int64]string // id -> current name (renames update this)
|
||||
teamOIDC map[int64][2]string
|
||||
teamDelete map[int64]bool // id -> true once DELETEd, for 404-on-redelete
|
||||
|
||||
// users backs GET /api/users for TerdutEscalationRule's username
|
||||
// resolution (DESIGN.md §4.3) -- a fixed, pre-seeded directory, since
|
||||
// nothing in this controller's own flow ever creates a user.
|
||||
users map[string]int64 // username -> id
|
||||
|
||||
// escalation backs PUT /api/teams/{id}/escalation -- an upsert
|
||||
// server-side (confirmed against source), so this is just "the last
|
||||
// body PUT for this team", keyed by teamID, with no separate create
|
||||
// step to model.
|
||||
escalation map[int64]tdclient.SetEscalationRequest
|
||||
|
||||
// switches/nextSwitchID/switchDelete back the dead man's switch
|
||||
// endpoints -- no unique-name constraint server-side (DESIGN.md §4.4),
|
||||
// so switches is keyed by id, not name, same as the real API's own
|
||||
// GET-list-and-match-by-name idempotent-create shape requires.
|
||||
nextSwitchID int64
|
||||
switches map[int64]map[int64]tdclient.DeadmanSwitch // teamID -> switchID -> switch
|
||||
switchDelete map[int64]bool // switchID -> true once DELETEd, for 404-on-redelete
|
||||
}
|
||||
|
||||
func newFakeTerdutServer() (*fakeTerdutServer, *httptest.Server) {
|
||||
f := &fakeTerdutServer{
|
||||
accounts: map[string]int64{},
|
||||
keyMints: map[int64]int{},
|
||||
teams: map[string]int64{},
|
||||
teamNames: map[int64]string{},
|
||||
teamOIDC: map[int64][2]string{},
|
||||
teamDelete: map[int64]bool{},
|
||||
accounts: map[string]int64{},
|
||||
keyMints: map[int64]int{},
|
||||
teams: map[string]int64{},
|
||||
teamNames: map[int64]string{},
|
||||
teamOIDC: map[int64][2]string{},
|
||||
teamDelete: map[int64]bool{},
|
||||
users: map[string]int64{},
|
||||
escalation: map[int64]tdclient.SetEscalationRequest{},
|
||||
switches: map[int64]map[int64]tdclient.DeadmanSwitch{},
|
||||
switchDelete: map[int64]bool{},
|
||||
}
|
||||
return f, httptest.NewServer(f)
|
||||
}
|
||||
|
||||
// seedUser registers a username the fake GET /api/users will return --
|
||||
// called from test setup, before the controller under test ever runs.
|
||||
// Callers read the assigned id back from f.users themselves, so this has
|
||||
// nothing left to return.
|
||||
func (f *fakeTerdutServer) seedUser(username string) {
|
||||
f.mu.Lock()
|
||||
defer f.mu.Unlock()
|
||||
f.nextID++
|
||||
f.users[username] = f.nextID
|
||||
}
|
||||
|
||||
func (f *fakeTerdutServer) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
||||
f.mu.Lock()
|
||||
defer f.mu.Unlock()
|
||||
@@ -137,6 +173,16 @@ func (f *fakeTerdutServer) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
writeJSON(w, http.StatusOK, []tdclient.Team{{ID: id, Name: f.teamNames[id]}})
|
||||
|
||||
case r.URL.Path == "/api/users" && r.Method == http.MethodGet:
|
||||
// No query filter -- GetUserByUsername fetches the whole list and
|
||||
// matches client-side (confirmed against source: no server-side
|
||||
// filter either), so the fake does the same.
|
||||
users := make([]tdclient.User, 0, len(f.users))
|
||||
for name, id := range f.users {
|
||||
users = append(users, tdclient.User{ID: id, Username: name})
|
||||
}
|
||||
writeJSON(w, http.StatusOK, users)
|
||||
|
||||
default:
|
||||
if id, name, ok := parseKeysPath(r.URL.Path); ok && r.Method == http.MethodPost {
|
||||
f.keyMints[id]++
|
||||
@@ -146,34 +192,21 @@ func (f *fakeTerdutServer) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
||||
})
|
||||
return
|
||||
}
|
||||
if id, ok := parseTeamPath(r.URL.Path); ok {
|
||||
f.handleTeamByID(w, r, id)
|
||||
if id, rest, ok := parseTeamSubPath(r.URL.Path); ok {
|
||||
f.handleTeamSubPath(w, r, id, rest)
|
||||
return
|
||||
}
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
}
|
||||
}
|
||||
|
||||
// handleTeamByID answers PUT /api/teams/{id}, PUT /api/teams/{id}/oidc-groups
|
||||
// and DELETE /api/teams/{id}.
|
||||
func (f *fakeTerdutServer) handleTeamByID(w http.ResponseWriter, r *http.Request, id int64) {
|
||||
oidcSuffix := fmt.Sprintf("/api/teams/%d/oidc-groups", id)
|
||||
|
||||
// handleTeamSubPath answers everything under /api/teams/{id}: PUT (rename),
|
||||
// DELETE, PUT .../oidc-groups, PUT .../escalation, and the dead man's
|
||||
// switch collection/item endpoints. rest is whatever parseTeamSubPath found
|
||||
// after "/api/teams/{id}" -- "" for the bare resource.
|
||||
func (f *fakeTerdutServer) handleTeamSubPath(w http.ResponseWriter, r *http.Request, id int64, rest string) {
|
||||
switch {
|
||||
case r.URL.Path == oidcSuffix && r.Method == http.MethodPut:
|
||||
var req struct {
|
||||
MemberGroup string `json:"member_group"`
|
||||
OwnerGroup string `json:"owner_group"`
|
||||
}
|
||||
_ = json.NewDecoder(r.Body).Decode(&req)
|
||||
if _, exists := f.teamNames[id]; !exists {
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
return
|
||||
}
|
||||
f.teamOIDC[id] = [2]string{req.MemberGroup, req.OwnerGroup}
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
|
||||
case r.URL.Path == fmt.Sprintf("/api/teams/%d", id) && r.Method == http.MethodPut:
|
||||
case rest == "" && r.Method == http.MethodPut:
|
||||
var req struct {
|
||||
Name string `json:"name"`
|
||||
}
|
||||
@@ -188,7 +221,7 @@ func (f *fakeTerdutServer) handleTeamByID(w http.ResponseWriter, r *http.Request
|
||||
f.teams[req.Name] = id
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
|
||||
case r.URL.Path == fmt.Sprintf("/api/teams/%d", id) && r.Method == http.MethodDelete:
|
||||
case rest == "" && r.Method == http.MethodDelete:
|
||||
name, exists := f.teamNames[id]
|
||||
if !exists {
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
@@ -199,23 +232,132 @@ func (f *fakeTerdutServer) handleTeamByID(w http.ResponseWriter, r *http.Request
|
||||
f.teamDelete[id] = true
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
|
||||
case rest == "/oidc-groups" && r.Method == http.MethodPut:
|
||||
var req struct {
|
||||
MemberGroup string `json:"member_group"`
|
||||
OwnerGroup string `json:"owner_group"`
|
||||
}
|
||||
_ = json.NewDecoder(r.Body).Decode(&req)
|
||||
if _, exists := f.teamNames[id]; !exists {
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
return
|
||||
}
|
||||
f.teamOIDC[id] = [2]string{req.MemberGroup, req.OwnerGroup}
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
|
||||
case rest == "/escalation" && r.Method == http.MethodPut:
|
||||
var req tdclient.SetEscalationRequest
|
||||
_ = json.NewDecoder(r.Body).Decode(&req)
|
||||
f.escalation[id] = req
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
|
||||
case rest == "/deadman/switches" && r.Method == http.MethodGet:
|
||||
existing := f.switches[id]
|
||||
out := make([]tdclient.DeadmanSwitch, 0, len(existing))
|
||||
for _, s := range existing {
|
||||
out = append(out, s)
|
||||
}
|
||||
writeJSON(w, http.StatusOK, out)
|
||||
|
||||
case rest == "/deadman/switches" && r.Method == http.MethodPost:
|
||||
var req deadmanSwitchFakeRequest
|
||||
_ = json.NewDecoder(r.Body).Decode(&req)
|
||||
f.nextSwitchID++
|
||||
switchID := f.nextSwitchID
|
||||
name := req.Name
|
||||
if name == "" {
|
||||
name = "derived-" + req.Matcher
|
||||
}
|
||||
sw := tdclient.DeadmanSwitch{
|
||||
ID: switchID, Name: name, Matcher: req.Matcher,
|
||||
TimeoutSeconds: req.TimeoutSeconds, Severity: req.Severity,
|
||||
}
|
||||
if f.switches[id] == nil {
|
||||
f.switches[id] = map[int64]tdclient.DeadmanSwitch{}
|
||||
}
|
||||
f.switches[id][switchID] = sw
|
||||
writeJSON(w, http.StatusCreated, sw)
|
||||
|
||||
case strings.HasPrefix(rest, "/deadman/switches/") && r.Method == http.MethodPut:
|
||||
switchID, ok := parseTrailingID(rest, "/deadman/switches/")
|
||||
if !ok {
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
return
|
||||
}
|
||||
if _, exists := f.switches[id][switchID]; !exists {
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
return
|
||||
}
|
||||
var req deadmanSwitchFakeRequest
|
||||
_ = json.NewDecoder(r.Body).Decode(&req)
|
||||
name := req.Name
|
||||
if name == "" {
|
||||
name = f.switches[id][switchID].Name
|
||||
}
|
||||
f.switches[id][switchID] = tdclient.DeadmanSwitch{
|
||||
ID: switchID, Name: name, Matcher: req.Matcher,
|
||||
TimeoutSeconds: req.TimeoutSeconds, Severity: req.Severity,
|
||||
}
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
|
||||
case strings.HasPrefix(rest, "/deadman/switches/") && r.Method == http.MethodDelete:
|
||||
switchID, ok := parseTrailingID(rest, "/deadman/switches/")
|
||||
if !ok {
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
return
|
||||
}
|
||||
if _, exists := f.switches[id][switchID]; !exists {
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
return
|
||||
}
|
||||
delete(f.switches[id], switchID)
|
||||
f.switchDelete[switchID] = true
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
|
||||
default:
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
}
|
||||
}
|
||||
|
||||
// parseTeamPath extracts the numeric id from "/api/teams/{id}" or
|
||||
// "/api/teams/{id}/oidc-groups" -- anything with more or fewer segments
|
||||
// doesn't match (handleTeamByID's own switch sorts out which of the two).
|
||||
func parseTeamPath(path string) (id int64, ok bool) {
|
||||
var parsedID int64
|
||||
if n, err := fmt.Sscanf(path, "/api/teams/%d/oidc-groups", &parsedID); err == nil && n == 1 {
|
||||
return parsedID, true
|
||||
// deadmanSwitchFakeRequest mirrors tdclient's own (unexported)
|
||||
// deadmanSwitchRequest -- the fake needs its own copy to decode the same
|
||||
// wire shape without reaching across package boundaries for an internal type.
|
||||
type deadmanSwitchFakeRequest struct {
|
||||
Name string `json:"name,omitempty"`
|
||||
Matcher string `json:"matcher"`
|
||||
TimeoutSeconds int64 `json:"timeout_seconds"`
|
||||
Severity string `json:"severity"`
|
||||
}
|
||||
|
||||
// parseTeamSubPath splits "/api/teams/{id}" from anything after it --
|
||||
// "" for an exact match, "/oidc-groups", "/escalation", "/deadman/switches"
|
||||
// or "/deadman/switches/{switchID}" otherwise. Doesn't itself validate the
|
||||
// suffix; handleTeamSubPath's own switch does that.
|
||||
func parseTeamSubPath(path string) (id int64, rest string, ok bool) {
|
||||
const prefix = "/api/teams/"
|
||||
if !strings.HasPrefix(path, prefix) {
|
||||
return 0, "", false
|
||||
}
|
||||
if n, err := fmt.Sscanf(path, "/api/teams/%d", &parsedID); err == nil && n == 1 {
|
||||
return parsedID, true
|
||||
trimmed := path[len(prefix):]
|
||||
parts := strings.SplitN(trimmed, "/", 2)
|
||||
parsedID, err := strconv.ParseInt(parts[0], 10, 64)
|
||||
if err != nil {
|
||||
return 0, "", false
|
||||
}
|
||||
return 0, false
|
||||
if len(parts) == 1 {
|
||||
return parsedID, "", true
|
||||
}
|
||||
return parsedID, "/" + parts[1], true
|
||||
}
|
||||
|
||||
// parseTrailingID parses the numeric id after prefix within rest, e.g.
|
||||
// parseTrailingID("/deadman/switches/7", "/deadman/switches/") -> 7, true.
|
||||
func parseTrailingID(rest, prefix string) (id int64, ok bool) {
|
||||
parsedID, err := strconv.ParseInt(strings.TrimPrefix(rest, prefix), 10, 64)
|
||||
if err != nil {
|
||||
return 0, false
|
||||
}
|
||||
return parsedID, true
|
||||
}
|
||||
|
||||
func parseKeysPath(path string) (id int64, mintName string, ok bool) {
|
||||
|
||||
Reference in New Issue
Block a user