e1103f2b7d
Credentials: the TerdutServer controller generates <name>-operator-key in the server's own namespace (owned by it) and hands it to the pods as TERDUT_OPERATOR_KEY; the server creates its instance-scoped account from it at every start. A replaced Secret rolls the pods. The bootstrap handshake, the checkpoint Secret, per-team service accounts and credentials Secrets, BootstrapStateLost and credentials.deletionPolicy are gone. CRDs: TerdutServer, TerdutTeam and TerdutAlertSource. TerdutEscalationRule and TerdutDeadmanSwitch become spec.escalation and spec.deadmanSwitches[] on the team (matched by name, extras removed); team invites are removed. A team is created under the identity <namespace>/<name> (external_id), so a retry, a lost status or a deleted team heal by repeating the same call, and a display name owned by another team is TeamNameTaken instead of an adoption. The server resolves escalation usernames (UnknownUser condition). OIDC claim names and trustEmail are spec fields. Fixes: query values are URL-escaped; every delete treats 404 as success; deleting a team no longer depends on allowedTeams consent; a switch or integration deleted on the server is recreated; unnamed switches take the CR's name. Cleanup: scaffold e2e test, AGENTS.md, devcontainer, unused config/ pieces and Client.Version() removed; DESIGN.md, README, ROADMAP and the demo (run-demo.sh, manifests) rewritten for the new design. Secret RBAC stays cluster-wide, now stated in DESIGN.md section 9. Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
35 lines
1.4 KiB
YAML
35 lines
1.4 KiB
YAML
resources:
|
|
# All RBAC will be applied under this service account in
|
|
# the deployment namespace. You may comment out this resource
|
|
# if your manager will use a service account that exists at
|
|
# runtime. Be sure to update RoleBinding and ClusterRoleBinding
|
|
# subjects if changing service account names.
|
|
- service_account.yaml
|
|
- role.yaml
|
|
- role_binding.yaml
|
|
- leader_election_role.yaml
|
|
- leader_election_role_binding.yaml
|
|
# The following RBAC configurations are used to protect
|
|
# the metrics endpoint with authn/authz. These configurations
|
|
# ensure that only authorized users and service accounts
|
|
# can access the metrics endpoint. Comment the following
|
|
# permissions if you want to disable this protection.
|
|
# More info: https://book.kubebuilder.io/reference/metrics.html
|
|
- metrics_auth_role.yaml
|
|
- metrics_auth_role_binding.yaml
|
|
- metrics_reader_role.yaml
|
|
# For each CRD, "Admin", "Editor" and "Viewer" roles are scaffolded by
|
|
# default, aiding admins in cluster management. Those roles are
|
|
# not used by the terdut-operator itself. You can comment the following lines
|
|
# if you do not want those helpers be installed with your Project.
|
|
- terdutalertsource_admin_role.yaml
|
|
- terdutalertsource_editor_role.yaml
|
|
- terdutalertsource_viewer_role.yaml
|
|
- terdutteam_admin_role.yaml
|
|
- terdutteam_editor_role.yaml
|
|
- terdutteam_viewer_role.yaml
|
|
- terdutserver_admin_role.yaml
|
|
- terdutserver_editor_role.yaml
|
|
- terdutserver_viewer_role.yaml
|
|
|