c97571c4c4
kubebuilder init --domain ryuvia.com --repo git.ryuvia.com/niklas/terdut-operator (--license none, no per-file header boilerplate -- terdut-server's source carries none either). Go 1.26.0/controller-runtime v0.25.0/controller-tools v0.22.0, whatever the current kubebuilder CLI (v4.16.0) scaffolds -- not pinned back to terdut-server's go 1.25.9, since this is a separate module with its own toolchain. Verified locally: build, vet, fmt all clean; `make lint` (golangci-lint, fetched into bin/) 0 issues; `make test` (controller-gen + setup-envtest, fetched into bin/, downloads real envtest binaries from storage.googleapis.com) passes. Dropped kubebuilder's default .github/workflows/* -- this org runs on Gitea, not GitHub; ci.yaml (next commit) is the only CI this repo gets.
21 lines
854 B
YAML
21 lines
854 B
YAML
resources:
|
|
# All RBAC will be applied under this service account in
|
|
# the deployment namespace. You may comment out this resource
|
|
# if your manager will use a service account that exists at
|
|
# runtime. Be sure to update RoleBinding and ClusterRoleBinding
|
|
# subjects if changing service account names.
|
|
- service_account.yaml
|
|
- role.yaml
|
|
- role_binding.yaml
|
|
- leader_election_role.yaml
|
|
- leader_election_role_binding.yaml
|
|
# The following RBAC configurations are used to protect
|
|
# the metrics endpoint with authn/authz. These configurations
|
|
# ensure that only authorized users and service accounts
|
|
# can access the metrics endpoint. Comment the following
|
|
# permissions if you want to disable this protection.
|
|
# More info: https://book.kubebuilder.io/reference/metrics.html
|
|
- metrics_auth_role.yaml
|
|
- metrics_auth_role_binding.yaml
|
|
- metrics_reader_role.yaml
|