Files
terdut-operator/internal/controller/terdutserver_credentials.go
T
Niklas Ye e1103f2b7d Authenticate with a seeded operator key; fold escalation and switches into TerdutTeam
Credentials: the TerdutServer controller generates <name>-operator-key in
the server's own namespace (owned by it) and hands it to the pods as
TERDUT_OPERATOR_KEY; the server creates its instance-scoped account from it
at every start. A replaced Secret rolls the pods. The bootstrap handshake,
the checkpoint Secret, per-team service accounts and credentials Secrets,
BootstrapStateLost and credentials.deletionPolicy are gone.

CRDs: TerdutServer, TerdutTeam and TerdutAlertSource. TerdutEscalationRule
and TerdutDeadmanSwitch become spec.escalation and spec.deadmanSwitches[]
on the team (matched by name, extras removed); team invites are removed.
A team is created under the identity <namespace>/<name> (external_id), so a
retry, a lost status or a deleted team heal by repeating the same call, and
a display name owned by another team is TeamNameTaken instead of an
adoption. The server resolves escalation usernames (UnknownUser condition).
OIDC claim names and trustEmail are spec fields.

Fixes: query values are URL-escaped; every delete treats 404 as success;
deleting a team no longer depends on allowedTeams consent; a switch or
integration deleted on the server is recreated; unnamed switches take the
CR's name.

Cleanup: scaffold e2e test, AGENTS.md, devcontainer, unused config/ pieces
and Client.Version() removed; DESIGN.md, README, ROADMAP and the demo
(run-demo.sh, manifests) rewritten for the new design. Secret RBAC stays
cluster-wide, now stated in DESIGN.md section 9.

Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
2026-10-09 14:56:22 +02:00

102 lines
3.7 KiB
Go

package controller
import (
"context"
"crypto/rand"
"crypto/sha256"
"encoding/hex"
"fmt"
corev1 "k8s.io/api/core/v1"
apierrors "k8s.io/apimachinery/pkg/api/errors"
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
"sigs.k8s.io/controller-runtime/pkg/client"
"sigs.k8s.io/controller-runtime/pkg/controller/controllerutil"
terdutv1alpha1 "git.ryuvia.com/niklas/terdut-operator/api/v1alpha1"
)
// operatorKeyDataKey is the data key of the operator key Secret.
const operatorKeyDataKey = "token"
// operatorKeyPrefix marks the key as a service-account credential in logs, the
// way terdut-server's own generated ones are.
const operatorKeyPrefix = "tdsa_"
// operatorKeySecretName is the Secret holding a TerdutServer's operator key. It
// lives beside the Deployment because the pod mounts it (TERDUT_OPERATOR_KEY)
// and a pod can only reference Secrets of its own namespace; it is owned by the
// TerdutServer, so deleting that deletes the key and a recreated one starts
// with a fresh one the server re-seeds on its next start.
func operatorKeySecretName(srv *terdutv1alpha1.TerdutServer) string {
return srv.Name + "-operator-key"
}
// reconcileOperatorKey returns this server's operator key, generating the Secret
// on first use. An existing Secret is never overwritten: the running server was
// seeded with that value, and replacing it would lock the operator out until
// every pod restarted.
func (r *TerdutServerReconciler) reconcileOperatorKey(ctx context.Context, srv *terdutv1alpha1.TerdutServer) (string, error) {
var secret corev1.Secret
key := client.ObjectKey{Namespace: srv.Namespace, Name: operatorKeySecretName(srv)}
err := r.Get(ctx, key, &secret)
if err == nil {
if v := string(secret.Data[operatorKeyDataKey]); v != "" {
return v, nil
}
// Present but empty or foreign: treat as ours to fill rather than
// failing every reconcile on it.
} else if !apierrors.IsNotFound(err) {
return "", err
}
raw := make([]byte, 24)
if _, err := rand.Read(raw); err != nil {
return "", fmt.Errorf("generating operator key: %w", err)
}
value := operatorKeyPrefix + hex.EncodeToString(raw)
secret = corev1.Secret{
ObjectMeta: metav1.ObjectMeta{Name: key.Name, Namespace: key.Namespace},
Data: map[string][]byte{operatorKeyDataKey: []byte(value)},
}
if err := controllerutil.SetControllerReference(srv, &secret, r.Scheme); err != nil {
return "", err
}
if err := r.Create(ctx, &secret); err != nil {
if apierrors.IsAlreadyExists(err) {
// Lost a race with a stale cache read: the next reconcile finds it.
return "", fmt.Errorf("operator key Secret %s appeared during creation; retrying", key.Name)
}
return "", err
}
return value, nil
}
// operatorKeyHash is a short digest of the key, stamped on the pod template so
// a replaced Secret rolls the Deployment: the server only reads the env var at
// start.
func operatorKeyHash(value string) string {
sum := sha256.Sum256([]byte(value))
return hex.EncodeToString(sum[:8])
}
// operatorKeyRef is the reference status.credentialsSecretRef reports.
func operatorKeyRef(srv *terdutv1alpha1.TerdutServer) *terdutv1alpha1.SecretKeyRef {
return &terdutv1alpha1.SecretKeyRef{Name: operatorKeySecretName(srv), Key: operatorKeyDataKey}
}
// readOperatorKey reads a TerdutServer's key from its own namespace, for the
// controllers that call the server's API.
func readOperatorKey(ctx context.Context, c client.Client, srv *terdutv1alpha1.TerdutServer) (string, error) {
var secret corev1.Secret
if err := c.Get(ctx, client.ObjectKey{Namespace: srv.Namespace, Name: operatorKeySecretName(srv)}, &secret); err != nil {
return "", err
}
v := string(secret.Data[operatorKeyDataKey])
if v == "" {
return "", fmt.Errorf("operator key Secret %s/%s is empty", srv.Namespace, secret.Name)
}
return v, nil
}