37 lines
1.2 KiB
Markdown
37 lines
1.2 KiB
Markdown
# Terdut operator
|
|
|
|
Aims to expose most config as CRD's, so end users can self-service over gitops.
|
|
|
|
See [DESIGN.md](./DESIGN.md) for the full design: CRD catalog and specs,
|
|
reconciliation semantics, bootstrap/auth, Postgres integration, RBAC, and the
|
|
relationship to `charts/terdut-server`. This README stays a short pitch; the
|
|
open questions it used to carry are now resolved decisions there (§2).
|
|
|
|
## CRD's
|
|
|
|
### terdutServers
|
|
Creates a server — Deployment, Service, database wiring, bootstrap, operator
|
|
credentials, and `allowedTeams` consent for cross-namespace teams. See
|
|
DESIGN.md §4.1, §4.6.
|
|
|
|
### terdutTeams
|
|
- team name
|
|
- oidc groups
|
|
- `serverRef` — explicit reference to its `TerdutServer`, may be in a
|
|
different namespace (one team owns the server, others self-service a
|
|
team against it), gated by that `TerdutServer`'s own `allowedTeams`
|
|
field (DESIGN.md §2, §4.1, §4.2, §4.6)
|
|
|
|
### terdutEscalationrules
|
|
- rule
|
|
- `teamRef` — explicit reference to its `TerdutTeam` (DESIGN.md §2, §4.3)
|
|
|
|
### terdutDeadmansswitches
|
|
- rule
|
|
- `teamRef` (DESIGN.md §4.4)
|
|
|
|
### terdutAlertSources
|
|
- `teamRef` (DESIGN.md §4.5)
|
|
- URL/key are generated by the server at creation and surfaced only via a
|
|
generated Secret, never set explicitly
|