8064876cb1
CI / test (push) Successful in 1m46s
paths, self-registration bootstrap)
Replaces the bring-your-own-only Stage 1 (commit 1be7cf2) wholesale, per
the redesign in the previous two commits: the operator creates every
server it manages, so self-registration (DESIGN.md §6) is the only
bootstrap path, and Deployment/Service/database management builds
together with it (ROADMAP.md Stage 1) rather than behind a separate
later stage.
Grounded in terdut-server's actual chart (charts/terdut-server/templates/
deployment.yaml, values.yaml), not reconstructed from DESIGN.md's
illustrative YAML alone -- env var names, the password-via-PGPASSWORD
convention, the Recreate deployment strategy, /healthz probes, and the
TERDUT_OPERATOR_MODE=true decision (always on here, unlike the chart's
default-off: every write this operator's own future controllers make
goes through a service account already) all match that source exactly.
- api/v1alpha1: full TerdutServerSpec (image, replicas, networking,
database, sweeper, deadman, notify, oidc, passwordLogin, allowedTeams).
spec.database is a oneOf (dsn xor postgresClusterRef) via CEL
XValidation. No spec.credentialsSecretRef -- removed entirely in the
prior redesign commit, not carried forward.
- internal/controller:
- terdutserver_deployment.go: Deployment + Service via CreateOrUpdate,
owned (OwnerReference), env built field-for-field against the chart.
- terdutserver_database.go: both §8 paths. The Zalando path resolves
the postgresql.acid.zalan.do CR by convention (database/role both
"terdut", matching every DESIGN.md example) and only ever confirms
its generated credentials Secret exists -- never reads the value,
same "wire a secretKeyRef, don't read it" posture the DSN path takes.
classifyClusterGetError is its own function specifically so the
CRD-not-installed case (meta.IsNoMatchError) is unit-testable without
a real client.
- terdutserver_bootstrap.go: self-registration, checkpointed against
both real crash windows (DESIGN.md §6 point 1) -- an admin-key
checkpoint Secret, and adopt-via-GET+mint-new-key on a 409 from
creating the service account. BootstrapStateLost is its own error
type so Reconcile can route it to a condition instead of an infinite
retry.
- terdutserver_controller.go: ties it together -- finalizer add, DB
resolution, Deployment/Service reconcile, wait for a ready replica,
bootstrap, Ready/Bootstrapped/DatabaseReady conditions. Finalizer on
delete only removes the generated Secrets: terdut-server's API can't
delete a user or service account, only revoke keys, so there's
nothing server-side to undo.
- internal/tdclient: added Bootstrap, CreateInstanceServiceAccount,
GetServiceAccountByName, CreateServiceAccountKey, matching
terdut-server's real handlers' request/response shapes (internal/api/
users.go, service_accounts.go in that repo) field-for-field.
- Tests: envtest suite covering the full DSN-path lifecycle end to end
(finalizer -> Deployment/Service -> simulated readiness -> real
bootstrap against an httptest.Server fake), the adopt-on-409 recovery
path, BootstrapStateLost, both Zalando outcomes (cluster not found;
cluster + Secret found -> real DSN -> Ready), and deletion. A minimal
test-only stub of the Zalando CRD (internal/controller/testdata) lets
envtest create fixture objects without a real postgres-operator
installed. 74.0%/44.7% coverage, 0 lint issues.
- Two things scoped down from §8's full ambition, called out in code and
ROADMAP.md rather than silently dropped: no live watch on the
Zalando-generated Secret for rotation (periodic resync notices
eventually, not immediately), no Gateway API HTTPRoute creation from
spec.networking (would add a new dependency; nothing about proving
bootstrap works depends on external ingress existing). Both are
near-term follow-ups.
Verified locally: make fmt lint test build all clean.
154 lines
6.2 KiB
Go
154 lines
6.2 KiB
Go
package controller
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"fmt"
|
|
"net/http"
|
|
|
|
corev1 "k8s.io/api/core/v1"
|
|
apierrors "k8s.io/apimachinery/pkg/api/errors"
|
|
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
|
"sigs.k8s.io/controller-runtime/pkg/client"
|
|
|
|
terdutv1alpha1 "git.ryuvia.com/niklas/terdut-operator/api/v1alpha1"
|
|
"git.ryuvia.com/niklas/terdut-operator/internal/tdclient"
|
|
)
|
|
|
|
// credentialsSecretDataKey is the fixed data key every generated
|
|
// credentials Secret this controller writes uses — "whatever a human chose"
|
|
// only applied to the bring-your-own input this design removed (DESIGN.md
|
|
// §6); every Secret this controller itself generates uses this one key.
|
|
const credentialsSecretDataKey = "token"
|
|
|
|
// bootstrapStateLostError is DESIGN.md §6's one genuinely pathological
|
|
// case: a checkpointed admin credential was used and then lost before the
|
|
// lasting credential it was for could be persisted. Distinct from a plain
|
|
// error so Reconcile can route it to a Ready: False condition (the
|
|
// documented recovery is delete-and-recreate, not an automatic retry) rather
|
|
// than treating it as a transient reconcile failure.
|
|
type bootstrapStateLostError struct{ detail string }
|
|
|
|
func (e *bootstrapStateLostError) Error() string {
|
|
return fmt.Sprintf(
|
|
"server reports already bootstrapped, but neither status.credentialsSecretRef nor a "+
|
|
"checkpointed admin credential exist here: %s. This TerdutServer cannot recover a "+
|
|
"credential on its own; delete and recreate it", e.detail)
|
|
}
|
|
|
|
// reconcileBootstrap implements DESIGN.md §6 point 1's self-registration
|
|
// flow, checkpointed against the two real crash windows in it rather than
|
|
// leaving them as theoretical gaps. Only called once
|
|
// srv.Status.CredentialsSecretRef is nil and the Deployment has a ready
|
|
// replica.
|
|
func (r *TerdutServerReconciler) reconcileBootstrap(ctx context.Context, srv *terdutv1alpha1.TerdutServer) error {
|
|
adminKey, err := r.getOrCreateCheckpointedAdminKey(ctx, srv)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
bc := r.NewClient(serviceURL(srv)).WithToken(adminKey)
|
|
instanceKey, err := r.getOrMintInstanceServiceAccountKey(ctx, bc)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
credsName := credentialsSecretName(srv)
|
|
if err := r.writeSecret(ctx, credsName, instanceKey); err != nil {
|
|
return err
|
|
}
|
|
srv.Status.CredentialsSecretRef = &terdutv1alpha1.SecretKeyRef{Name: credsName, Key: credentialsSecretDataKey}
|
|
|
|
// Best-effort: the checkpoint has done its job. Leaving it behind on a
|
|
// delete failure here isn't a correctness problem (the next reconcile
|
|
// finds status.CredentialsSecretRef already set and never looks at the
|
|
// checkpoint again) — it would just be an unused Secret sitting around,
|
|
// cleaned up for real by the finalizer on delete.
|
|
checkpoint := &corev1.Secret{ObjectMeta: metav1.ObjectMeta{Name: checkpointSecretName(srv), Namespace: r.OperatorNamespace}}
|
|
_ = r.Delete(ctx, checkpoint)
|
|
|
|
return nil
|
|
}
|
|
|
|
// getOrCreateCheckpointedAdminKey returns a usable admin key: from the
|
|
// checkpoint Secret if an earlier, interrupted attempt already got one, or
|
|
// freshly from /api/bootstrap, immediately checkpointed before it's used
|
|
// for anything else.
|
|
func (r *TerdutServerReconciler) getOrCreateCheckpointedAdminKey(ctx context.Context, srv *terdutv1alpha1.TerdutServer) (string, error) {
|
|
checkpointName := checkpointSecretName(srv)
|
|
|
|
var checkpoint corev1.Secret
|
|
err := r.Get(ctx, client.ObjectKey{Namespace: r.OperatorNamespace, Name: checkpointName}, &checkpoint)
|
|
switch {
|
|
case err == nil:
|
|
return string(checkpoint.Data[credentialsSecretDataKey]), nil
|
|
case !apierrors.IsNotFound(err):
|
|
return "", err
|
|
}
|
|
|
|
bc := r.NewClient(serviceURL(srv))
|
|
result, err := bc.Bootstrap(ctx, bootstrapUsername, bootstrapEmail)
|
|
if err != nil {
|
|
if statusErr, ok := errors.AsType[*tdclient.StatusError](err); ok && statusErr.Code == http.StatusForbidden {
|
|
// §1: this operator is the only thing that ever bootstraps a
|
|
// server it created, so a 403 here (no checkpoint, no
|
|
// status.credentialsSecretRef) means a prior reconcile already
|
|
// won this exact race and its checkpoint was lost afterward --
|
|
// the one case §6 doesn't try to paper over.
|
|
return "", &bootstrapStateLostError{detail: "/api/bootstrap returned 403"}
|
|
}
|
|
return "", fmt.Errorf("POST /api/bootstrap: %w", err)
|
|
}
|
|
|
|
if err := r.writeSecret(ctx, checkpointName, result.APIKey.Key); err != nil {
|
|
return "", fmt.Errorf("checkpointing admin key: %w", err)
|
|
}
|
|
return result.APIKey.Key, nil
|
|
}
|
|
|
|
// getOrMintInstanceServiceAccountKey mints the operator's own instance-
|
|
// scoped service account, or, if an earlier interrupted attempt already
|
|
// created it (409), adopts it and mints a fresh key rather than treating
|
|
// the conflict as an error (DESIGN.md §6 point 1, §5's general
|
|
// adopt-on-conflict rule).
|
|
func (r *TerdutServerReconciler) getOrMintInstanceServiceAccountKey(ctx context.Context, bc *tdclient.Client) (string, error) {
|
|
result, err := bc.CreateInstanceServiceAccount(ctx, serviceAccountName)
|
|
if err == nil {
|
|
return result.Key.Key, nil
|
|
}
|
|
|
|
statusErr, ok := errors.AsType[*tdclient.StatusError](err)
|
|
if !ok || statusErr.Code != http.StatusConflict {
|
|
return "", fmt.Errorf("POST /api/service-accounts: %w", err)
|
|
}
|
|
|
|
sa, err := bc.GetServiceAccountByName(ctx, serviceAccountName)
|
|
if err != nil {
|
|
return "", fmt.Errorf("GET /api/service-accounts?name=%s (adopting after 409): %w", serviceAccountName, err)
|
|
}
|
|
if sa == nil {
|
|
return "", fmt.Errorf("POST /api/service-accounts 409'd for %q but GET found nothing", serviceAccountName)
|
|
}
|
|
key, err := bc.CreateServiceAccountKey(ctx, sa.ID, "initial")
|
|
if err != nil {
|
|
return "", fmt.Errorf("POST /api/service-accounts/%d/keys (adopting after 409): %w", sa.ID, err)
|
|
}
|
|
return key.Key, nil
|
|
}
|
|
|
|
// writeSecret creates or replaces a Secret in the operator's own namespace
|
|
// holding one raw value under credentialsSecretDataKey.
|
|
func (r *TerdutServerReconciler) writeSecret(ctx context.Context, name, rawValue string) error {
|
|
secret := &corev1.Secret{
|
|
ObjectMeta: metav1.ObjectMeta{Name: name, Namespace: r.OperatorNamespace},
|
|
Data: map[string][]byte{credentialsSecretDataKey: []byte(rawValue)},
|
|
}
|
|
if err := r.Create(ctx, secret); err != nil {
|
|
if apierrors.IsAlreadyExists(err) {
|
|
return r.Update(ctx, secret)
|
|
}
|
|
return err
|
|
}
|
|
return nil
|
|
}
|