fb9e6a38dc
CI / test (push) Has been cancelled
Both child CRDs resolve their own teamRef -> TerdutTeam.status via the new
shared resolveTeamAndClient helper (childref.go), never chaining up to
TerdutServer (DESIGN.md §5) -- TerdutTeam.status.serverEndpoint, added in
this same stage, is what makes that literally true.
TerdutEscalationRule: one PUT /api/teams/{id}/escalation per reconcile
(an upsert server-side, confirmed against source), resolving each "user"
target's username to a user_id via GET /api/users first and reporting
Ready: False, reason: UnknownUser if it doesn't resolve. No DELETE exists
for this resource, so its delete path PUTs an empty policy as the closest
available undo.
TerdutDeadmanSwitch: real create/update-in-place/delete, using
terdut-server v0.33.0's PUT (added specifically for this operator). No
unique-name constraint server-side, so idempotent-create here is
GET-list-and-match-by-name rather than adopt-on-409.
Extends tdclient with User/GetUserByUsername, the escalation request types
+ SetEscalation, and DeadmanSwitch + its CRUD methods. Also folds
ConditionTeamReady into the single shared ConditionReady constant, since
both were literally "Ready" and Stage 3 would otherwise have needed a
third same-valued constant.
internal/controller/terdutserver_controller_test.go's fakeTerdutServer
grows GET /api/users, PUT .../escalation, and the full dead man's switch
collection/item routes, replacing the old parseTeamPath/handleTeamByID
pair with a more general parseTeamSubPath/handleTeamSubPath dispatcher
that still covers every existing Stage 1/2 route unchanged.
make fmt lint test build all clean; envtest coverage for
internal/controller: 50.5% -> 71.7%.
38 lines
1.5 KiB
YAML
38 lines
1.5 KiB
YAML
resources:
|
|
# All RBAC will be applied under this service account in
|
|
# the deployment namespace. You may comment out this resource
|
|
# if your manager will use a service account that exists at
|
|
# runtime. Be sure to update RoleBinding and ClusterRoleBinding
|
|
# subjects if changing service account names.
|
|
- service_account.yaml
|
|
- role.yaml
|
|
- role_binding.yaml
|
|
- leader_election_role.yaml
|
|
- leader_election_role_binding.yaml
|
|
# The following RBAC configurations are used to protect
|
|
# the metrics endpoint with authn/authz. These configurations
|
|
# ensure that only authorized users and service accounts
|
|
# can access the metrics endpoint. Comment the following
|
|
# permissions if you want to disable this protection.
|
|
# More info: https://book.kubebuilder.io/reference/metrics.html
|
|
- metrics_auth_role.yaml
|
|
- metrics_auth_role_binding.yaml
|
|
- metrics_reader_role.yaml
|
|
# For each CRD, "Admin", "Editor" and "Viewer" roles are scaffolded by
|
|
# default, aiding admins in cluster management. Those roles are
|
|
# not used by the terdut-operator itself. You can comment the following lines
|
|
# if you do not want those helpers be installed with your Project.
|
|
- terdutdeadmanswitch_admin_role.yaml
|
|
- terdutdeadmanswitch_editor_role.yaml
|
|
- terdutdeadmanswitch_viewer_role.yaml
|
|
- terdutescalationrule_admin_role.yaml
|
|
- terdutescalationrule_editor_role.yaml
|
|
- terdutescalationrule_viewer_role.yaml
|
|
- terdutteam_admin_role.yaml
|
|
- terdutteam_editor_role.yaml
|
|
- terdutteam_viewer_role.yaml
|
|
- terdutserver_admin_role.yaml
|
|
- terdutserver_editor_role.yaml
|
|
- terdutserver_viewer_role.yaml
|
|
|