package controller import ( "context" "crypto/rand" "crypto/sha256" "encoding/hex" "fmt" corev1 "k8s.io/api/core/v1" apierrors "k8s.io/apimachinery/pkg/api/errors" metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" "sigs.k8s.io/controller-runtime/pkg/client" "sigs.k8s.io/controller-runtime/pkg/controller/controllerutil" terdutv1alpha1 "git.ryuvia.com/niklas/terdut-operator/api/v1alpha1" ) // operatorKeyDataKey is the data key of the operator key Secret. const operatorKeyDataKey = "token" // operatorKeyPrefix marks the key as a service-account credential in logs, the // way terdut-server's own generated ones are. const operatorKeyPrefix = "tdsa_" // operatorKeySecretName is the Secret holding a TerdutServer's operator key. It // lives beside the Deployment because the pod mounts it (TERDUT_OPERATOR_KEY) // and a pod can only reference Secrets of its own namespace; it is owned by the // TerdutServer, so deleting that deletes the key and a recreated one starts // with a fresh one the server re-seeds on its next start. func operatorKeySecretName(srv *terdutv1alpha1.TerdutServer) string { return srv.Name + "-operator-key" } // reconcileOperatorKey returns this server's operator key, generating the Secret // on first use. An existing Secret is never overwritten: the running server was // seeded with that value, and replacing it would lock the operator out until // every pod restarted. func (r *TerdutServerReconciler) reconcileOperatorKey(ctx context.Context, srv *terdutv1alpha1.TerdutServer) (string, error) { var secret corev1.Secret key := client.ObjectKey{Namespace: srv.Namespace, Name: operatorKeySecretName(srv)} err := r.Get(ctx, key, &secret) if err == nil { if v := string(secret.Data[operatorKeyDataKey]); v != "" { return v, nil } // Present but empty or foreign: treat as ours to fill rather than // failing every reconcile on it. } else if !apierrors.IsNotFound(err) { return "", err } raw := make([]byte, 24) if _, err := rand.Read(raw); err != nil { return "", fmt.Errorf("generating operator key: %w", err) } value := operatorKeyPrefix + hex.EncodeToString(raw) secret = corev1.Secret{ ObjectMeta: metav1.ObjectMeta{Name: key.Name, Namespace: key.Namespace}, Data: map[string][]byte{operatorKeyDataKey: []byte(value)}, } if err := controllerutil.SetControllerReference(srv, &secret, r.Scheme); err != nil { return "", err } if err := r.Create(ctx, &secret); err != nil { if apierrors.IsAlreadyExists(err) { // Lost a race with a stale cache read: the next reconcile finds it. return "", fmt.Errorf("operator key Secret %s appeared during creation; retrying", key.Name) } return "", err } return value, nil } // operatorKeyHash is a short digest of the key, stamped on the pod template so // a replaced Secret rolls the Deployment: the server only reads the env var at // start. func operatorKeyHash(value string) string { sum := sha256.Sum256([]byte(value)) return hex.EncodeToString(sum[:8]) } // operatorKeyRef is the reference status.credentialsSecretRef reports. func operatorKeyRef(srv *terdutv1alpha1.TerdutServer) *terdutv1alpha1.SecretKeyRef { return &terdutv1alpha1.SecretKeyRef{Name: operatorKeySecretName(srv), Key: operatorKeyDataKey} } // readOperatorKey reads a TerdutServer's key from its own namespace, for the // controllers that call the server's API. func readOperatorKey(ctx context.Context, c client.Client, srv *terdutv1alpha1.TerdutServer) (string, error) { var secret corev1.Secret if err := c.Get(ctx, client.ObjectKey{Namespace: srv.Namespace, Name: operatorKeySecretName(srv)}, &secret); err != nil { return "", err } v := string(secret.Data[operatorKeyDataKey]) if v == "" { return "", fmt.Errorf("operator key Secret %s/%s is empty", srv.Namespace, secret.Name) } return v, nil }