e1103f2b7d
Credentials: the TerdutServer controller generates <name>-operator-key in the server's own namespace (owned by it) and hands it to the pods as TERDUT_OPERATOR_KEY; the server creates its instance-scoped account from it at every start. A replaced Secret rolls the pods. The bootstrap handshake, the checkpoint Secret, per-team service accounts and credentials Secrets, BootstrapStateLost and credentials.deletionPolicy are gone. CRDs: TerdutServer, TerdutTeam and TerdutAlertSource. TerdutEscalationRule and TerdutDeadmanSwitch become spec.escalation and spec.deadmanSwitches[] on the team (matched by name, extras removed); team invites are removed. A team is created under the identity <namespace>/<name> (external_id), so a retry, a lost status or a deleted team heal by repeating the same call, and a display name owned by another team is TeamNameTaken instead of an adoption. The server resolves escalation usernames (UnknownUser condition). OIDC claim names and trustEmail are spec fields. Fixes: query values are URL-escaped; every delete treats 404 as success; deleting a team no longer depends on allowedTeams consent; a switch or integration deleted on the server is recreated; unnamed switches take the CR's name. Cleanup: scaffold e2e test, AGENTS.md, devcontainer, unused config/ pieces and Client.Version() removed; DESIGN.md, README, ROADMAP and the demo (run-demo.sh, manifests) rewritten for the new design. Secret RBAC stays cluster-wide, now stated in DESIGN.md section 9. Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
102 lines
3.7 KiB
Go
102 lines
3.7 KiB
Go
package controller
|
|
|
|
import (
|
|
"context"
|
|
"crypto/rand"
|
|
"crypto/sha256"
|
|
"encoding/hex"
|
|
"fmt"
|
|
|
|
corev1 "k8s.io/api/core/v1"
|
|
apierrors "k8s.io/apimachinery/pkg/api/errors"
|
|
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
|
"sigs.k8s.io/controller-runtime/pkg/client"
|
|
"sigs.k8s.io/controller-runtime/pkg/controller/controllerutil"
|
|
|
|
terdutv1alpha1 "git.ryuvia.com/niklas/terdut-operator/api/v1alpha1"
|
|
)
|
|
|
|
// operatorKeyDataKey is the data key of the operator key Secret.
|
|
const operatorKeyDataKey = "token"
|
|
|
|
// operatorKeyPrefix marks the key as a service-account credential in logs, the
|
|
// way terdut-server's own generated ones are.
|
|
const operatorKeyPrefix = "tdsa_"
|
|
|
|
// operatorKeySecretName is the Secret holding a TerdutServer's operator key. It
|
|
// lives beside the Deployment because the pod mounts it (TERDUT_OPERATOR_KEY)
|
|
// and a pod can only reference Secrets of its own namespace; it is owned by the
|
|
// TerdutServer, so deleting that deletes the key and a recreated one starts
|
|
// with a fresh one the server re-seeds on its next start.
|
|
func operatorKeySecretName(srv *terdutv1alpha1.TerdutServer) string {
|
|
return srv.Name + "-operator-key"
|
|
}
|
|
|
|
// reconcileOperatorKey returns this server's operator key, generating the Secret
|
|
// on first use. An existing Secret is never overwritten: the running server was
|
|
// seeded with that value, and replacing it would lock the operator out until
|
|
// every pod restarted.
|
|
func (r *TerdutServerReconciler) reconcileOperatorKey(ctx context.Context, srv *terdutv1alpha1.TerdutServer) (string, error) {
|
|
var secret corev1.Secret
|
|
key := client.ObjectKey{Namespace: srv.Namespace, Name: operatorKeySecretName(srv)}
|
|
err := r.Get(ctx, key, &secret)
|
|
if err == nil {
|
|
if v := string(secret.Data[operatorKeyDataKey]); v != "" {
|
|
return v, nil
|
|
}
|
|
// Present but empty or foreign: treat as ours to fill rather than
|
|
// failing every reconcile on it.
|
|
} else if !apierrors.IsNotFound(err) {
|
|
return "", err
|
|
}
|
|
|
|
raw := make([]byte, 24)
|
|
if _, err := rand.Read(raw); err != nil {
|
|
return "", fmt.Errorf("generating operator key: %w", err)
|
|
}
|
|
value := operatorKeyPrefix + hex.EncodeToString(raw)
|
|
|
|
secret = corev1.Secret{
|
|
ObjectMeta: metav1.ObjectMeta{Name: key.Name, Namespace: key.Namespace},
|
|
Data: map[string][]byte{operatorKeyDataKey: []byte(value)},
|
|
}
|
|
if err := controllerutil.SetControllerReference(srv, &secret, r.Scheme); err != nil {
|
|
return "", err
|
|
}
|
|
if err := r.Create(ctx, &secret); err != nil {
|
|
if apierrors.IsAlreadyExists(err) {
|
|
// Lost a race with a stale cache read: the next reconcile finds it.
|
|
return "", fmt.Errorf("operator key Secret %s appeared during creation; retrying", key.Name)
|
|
}
|
|
return "", err
|
|
}
|
|
return value, nil
|
|
}
|
|
|
|
// operatorKeyHash is a short digest of the key, stamped on the pod template so
|
|
// a replaced Secret rolls the Deployment: the server only reads the env var at
|
|
// start.
|
|
func operatorKeyHash(value string) string {
|
|
sum := sha256.Sum256([]byte(value))
|
|
return hex.EncodeToString(sum[:8])
|
|
}
|
|
|
|
// operatorKeyRef is the reference status.credentialsSecretRef reports.
|
|
func operatorKeyRef(srv *terdutv1alpha1.TerdutServer) *terdutv1alpha1.SecretKeyRef {
|
|
return &terdutv1alpha1.SecretKeyRef{Name: operatorKeySecretName(srv), Key: operatorKeyDataKey}
|
|
}
|
|
|
|
// readOperatorKey reads a TerdutServer's key from its own namespace, for the
|
|
// controllers that call the server's API.
|
|
func readOperatorKey(ctx context.Context, c client.Client, srv *terdutv1alpha1.TerdutServer) (string, error) {
|
|
var secret corev1.Secret
|
|
if err := c.Get(ctx, client.ObjectKey{Namespace: srv.Namespace, Name: operatorKeySecretName(srv)}, &secret); err != nil {
|
|
return "", err
|
|
}
|
|
v := string(secret.Data[operatorKeyDataKey])
|
|
if v == "" {
|
|
return "", fmt.Errorf("operator key Secret %s/%s is empty", srv.Namespace, secret.Name)
|
|
}
|
|
return v, nil
|
|
}
|