048f4448c4
CI / test (push) Successful in 1m34s
Covers webhook Secret generation/ownership (DESIGN.md §4.5, §7), the
WebhookSecretLost fail-closed condition, and the kind-change
delete-and-recreate rotation path.
Idempotent-create here is deliberately neither adopt-on-409
(Team/service-account) nor list-and-match-by-name (TerdutDeadmanSwitch):
terdut-server shows the webhook key exactly once, at creation, and never
again, so no server-side lookup could ever recover it after a crash.
Instead the generated webhook Secret itself -- written immediately after
the POST, before status is ever touched -- is this CR's only durable
record that a create already succeeded; found with status.integrationID
still unset on a later reconcile, it's read back directly rather than
POSTing a second, orphaned integration. Found missing with
status.integrationID *set* instead, that's the already-designed
WebhookSecretLost case: fail closed, not self-healed, since the key is
genuinely gone and recreating it would rotate a live webhook URL with no
spec change to explain why.
Renaming (PATCH) never touches the key, so it's applied unconditionally
every reconcile, same as the escalation policy's whole-policy PUT. A
spec.kind change is the one case with no in-place update verb at all:
DELETE the old integration, delete the stale webhook Secret, then run the
same create path fresh -- fires a Warning event since this breaks whatever
still sends to the old URL.
Also: fakeTerdutServer grows POST/PATCH/DELETE .../integrations routes
behind a new handleIntegrationSubPath, split out of handleTeamSubPath to
stay under gocyclo's threshold; three goconst-flagged test literals
("does-not-exist", "unready") and one unparam-flagged test helper
parameter (bootstrapReadyTerdutServer's always-"default" namespace) get
shared/removed now that a fourth same-shaped caller made the repetition
concrete enough for the linter to flag.
DESIGN.md §13 gains one honest gap found while grounding this stage, not
introduced by it: no child CRD specially detects a mid-life teamRef
change; all three always resolve spec.teamRef fresh and trust the
already-stored server-side id remains valid there.
make fmt lint test build all clean; internal/controller envtest coverage
holds at 71.6%.
41 lines
1.6 KiB
YAML
41 lines
1.6 KiB
YAML
resources:
|
|
# All RBAC will be applied under this service account in
|
|
# the deployment namespace. You may comment out this resource
|
|
# if your manager will use a service account that exists at
|
|
# runtime. Be sure to update RoleBinding and ClusterRoleBinding
|
|
# subjects if changing service account names.
|
|
- service_account.yaml
|
|
- role.yaml
|
|
- role_binding.yaml
|
|
- leader_election_role.yaml
|
|
- leader_election_role_binding.yaml
|
|
# The following RBAC configurations are used to protect
|
|
# the metrics endpoint with authn/authz. These configurations
|
|
# ensure that only authorized users and service accounts
|
|
# can access the metrics endpoint. Comment the following
|
|
# permissions if you want to disable this protection.
|
|
# More info: https://book.kubebuilder.io/reference/metrics.html
|
|
- metrics_auth_role.yaml
|
|
- metrics_auth_role_binding.yaml
|
|
- metrics_reader_role.yaml
|
|
# For each CRD, "Admin", "Editor" and "Viewer" roles are scaffolded by
|
|
# default, aiding admins in cluster management. Those roles are
|
|
# not used by the terdut-operator itself. You can comment the following lines
|
|
# if you do not want those helpers be installed with your Project.
|
|
- terdutalertsource_admin_role.yaml
|
|
- terdutalertsource_editor_role.yaml
|
|
- terdutalertsource_viewer_role.yaml
|
|
- terdutdeadmanswitch_admin_role.yaml
|
|
- terdutdeadmanswitch_editor_role.yaml
|
|
- terdutdeadmanswitch_viewer_role.yaml
|
|
- terdutescalationrule_admin_role.yaml
|
|
- terdutescalationrule_editor_role.yaml
|
|
- terdutescalationrule_viewer_role.yaml
|
|
- terdutteam_admin_role.yaml
|
|
- terdutteam_editor_role.yaml
|
|
- terdutteam_viewer_role.yaml
|
|
- terdutserver_admin_role.yaml
|
|
- terdutserver_editor_role.yaml
|
|
- terdutserver_viewer_role.yaml
|
|
|