40 lines
1.4 KiB
Markdown
40 lines
1.4 KiB
Markdown
# Terdut operator
|
|
|
|
Aims to expose most config as CRD's, so end users can self-service over gitops.
|
|
|
|
See [DESIGN.md](./DESIGN.md) for the full design: CRD catalog and specs,
|
|
reconciliation semantics, bootstrap/auth, Postgres integration, RBAC, and the
|
|
relationship to `charts/terdut-server`. This README stays a short pitch; the
|
|
open questions it used to carry are now resolved decisions there (§2).
|
|
|
|
## CRD's
|
|
|
|
### terdutServers
|
|
Creates a server — Deployment, Service, database wiring, bootstrap, operator
|
|
credentials. See DESIGN.md §4.1.
|
|
|
|
### terdutTeams
|
|
- team name
|
|
- oidc groups
|
|
- `serverRef` — explicit reference to its `TerdutServer`, may be in a
|
|
different namespace (one team owns the server, others self-service a
|
|
team against it), gated by a `TerdutServerReferenceGrant` in the
|
|
server's namespace (DESIGN.md §2, §4.2, §4.6)
|
|
|
|
### terdutServerReferenceGrants
|
|
- lives in the `TerdutServer`'s namespace; lists which other namespaces'
|
|
`TerdutTeam` objects may reference it (DESIGN.md §4.6)
|
|
|
|
### terdutEscalationrules
|
|
- rule
|
|
- `teamRef` — explicit reference to its `TerdutTeam` (DESIGN.md §2, §4.3)
|
|
|
|
### terdutDeadmansswitches
|
|
- rule
|
|
- `teamRef` (DESIGN.md §4.4)
|
|
|
|
### terdutAlertSources
|
|
- `teamRef` (DESIGN.md §4.5)
|
|
- URL/key are generated by the server at creation and surfaced only via a
|
|
generated Secret, never set explicitly
|