Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions class/capi-provider-talos.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ parameters:
output_path: .
- input_paths:
- ${_base_directory}/component/main.jsonnet
- ${_base_directory}/component/ca-fact.jsonnet
input_type: jsonnet
output_path: .
- input_paths:
Expand Down
2 changes: 2 additions & 0 deletions class/defaults.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,8 @@ parameters:
multi_tenant: true
namespace: syn-cluster-api

clusterName: ${cluster:name}

images:
capi-bootstrap-provider-talos:
registry: ghcr.io
Expand Down
111 changes: 111 additions & 0 deletions component/ca-fact.jsonnet
Original file line number Diff line number Diff line change
@@ -0,0 +1,111 @@
local esp = import 'lib/espejote.libsonnet';
local kap = import 'lib/kapitan.libjsonnet';
local kube = import 'lib/kube.libjsonnet';
local inv = kap.inventory();

local params = inv.parameters.capi_provider_talos;
local ca_secret_name = '%s-ca' % params.clusterName;

local syn_namespace = 'syn';

local sa = kube.ServiceAccount('cluster-ca-dynamic-fact-manager') {
metadata+: {
namespace: params.namespace,
},
};

local syn_role = kube.Role('cluster:ca-dynamic-fact-manager') {
Comment thread
HappyTetrahedron marked this conversation as resolved.
Outdated
metadata+: {
namespace: syn_namespace,
},
rules: [
{
apiGroups: [ '' ],
resources: [ 'configmaps' ],
verbs: [ 'get', 'list', 'watch' ],
},
{
apiGroups: [ '' ],
resources: [ 'configmaps' ],
resourceNames: [ 'capi-ca-fact' ],
Comment thread
HappyTetrahedron marked this conversation as resolved.
Outdated
verbs: [ 'create', 'update', 'patch' ],
},
],
};

local role = kube.Role('cluster:ca-dynamic-fact-manager') {
Comment thread
HappyTetrahedron marked this conversation as resolved.
Outdated
metadata+: {
namespace: params.namespace,
},
rules: [
{
apiGroups: [ '' ],
resources: [ 'secrets' ],
resourceNames: [ ca_secret_name ],
verbs: [ 'get', 'list', 'watch' ],
},
],
};

local syn_rolebinding =
kube.RoleBinding('cluster:ca-dynamic-fact-manager') {
Comment thread
HappyTetrahedron marked this conversation as resolved.
Outdated
metadata+: {
namespace: syn_namespace,
},
roleRef_: syn_role,
subjects_: [ sa ],
};

local rolebinding =
kube.RoleBinding('cluster:ca-dynamic-fact-manager') {
Comment thread
HappyTetrahedron marked this conversation as resolved.
Outdated
metadata+: {
namespace: params.namespace,
},
roleRef_: role,
subjects_: [ sa ],
};


local mr = esp.managedResource('cluster-ca-dynamic-fact', params.namespace) {
spec: {
// Set force=true so we can take ownership of previously manually edited
// fields in `data`.
applyOptions: { force: true },
serviceAccountRef: { name: sa.metadata.name },
context: [
{
name: 'source',
resource: {
apiVersion: 'v1',
kind: 'Secret',
name: ca_secret_name,
},
},
],
triggers: [
{
name: 'source',
watchContextResource: {
name: 'source',
},
},
{
name: 'target',
watchResource: {
apiVersion: 'v1',
kind: 'ConfigMap',
namespace: syn_namespace,
name: 'capi-ca-fact',
Comment thread
HappyTetrahedron marked this conversation as resolved.
Outdated
},
},
],
template: importstr 'espejote-templates/manage-ca-fact.jsonnet',
},
};

if std.member(inv.applications, 'espejote') then {
cluster_ca_dynamic_fact: [ sa, role, rolebinding, syn_role, syn_rolebinding, mr ],
} else std.trace(
'Not rendering Espejote-managed CA fact because component-espejote is missing.',
{}
)
22 changes: 22 additions & 0 deletions component/espejote-templates/manage-ca-fact.jsonnet
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
local esp = import 'espejote.libsonnet';
local src =
local srcs = esp.context().source;
assert std.length(srcs) == 1 : 'Expected source context to have length 1';
srcs[0];
{
apiVersion: 'v1',
kind: 'ConfigMap',
metadata: {
name: 'capi-ca-fact',
Comment thread
HappyTetrahedron marked this conversation as resolved.
Outdated
namespace: 'syn',
labels: {
'app.kubernetes.io/managed-by': 'espejote',
'steward.syn.tools/include-facts': '',
},
},
data: {
facts: std.manifestJsonMinified({
talosAPICertificateAuthorityData: src.data['tls.crt'],
}),
},
}
5 changes: 5 additions & 0 deletions tests/defaults.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,13 +2,18 @@

applications:
- capi-core
- espejote

parameters:
kapitan:
dependencies:
- type: https
source: https://raw.githubusercontent.com/projectsyn/component-capi-core/master/lib/capi-core.libsonnet
output_path: vendor/lib/capi-core.libsonnet
- type: https
source: https://raw.githubusercontent.com/projectsyn/component-espejote/master/lib/espejote.libsonnet
output_path: vendor/lib/espejote.libsonnet

capi_core:
clusterName: c-holy-fire-1337
namespace: syn-cluster-api
144 changes: 144 additions & 0 deletions tests/golden/defaults/capi-provider-talos/cluster_ca_dynamic_fact.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,144 @@
apiVersion: v1
kind: ServiceAccount
metadata:
annotations: {}
labels:
name: cluster-ca-dynamic-fact-manager
name: cluster-ca-dynamic-fact-manager
namespace: syn-cluster-api
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
annotations: {}
labels:
name: cluster-ca-dynamic-fact-manager
name: cluster:ca-dynamic-fact-manager
namespace: syn-cluster-api
rules:
- apiGroups:
- ''
resourceNames:
- c-green-test-1234-ca
resources:
- secrets
verbs:
- get
- list
- watch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
annotations: {}
labels:
name: cluster-ca-dynamic-fact-manager
name: cluster:ca-dynamic-fact-manager
namespace: syn-cluster-api
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: cluster:ca-dynamic-fact-manager
subjects:
- kind: ServiceAccount
name: cluster-ca-dynamic-fact-manager
namespace: syn-cluster-api
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
annotations: {}
labels:
name: cluster-ca-dynamic-fact-manager
name: cluster:ca-dynamic-fact-manager
namespace: syn
rules:
- apiGroups:
- ''
resources:
- configmaps
verbs:
- get
- list
- watch
- apiGroups:
- ''
resourceNames:
- capi-ca-fact
resources:
- configmaps
verbs:
- create
- update
- patch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
annotations: {}
labels:
name: cluster-ca-dynamic-fact-manager
name: cluster:ca-dynamic-fact-manager
namespace: syn
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: cluster:ca-dynamic-fact-manager
subjects:
- kind: ServiceAccount
name: cluster-ca-dynamic-fact-manager
namespace: syn-cluster-api
---
apiVersion: espejote.io/v1alpha1
kind: ManagedResource
metadata:
annotations:
argocd.argoproj.io/sync-options: SkipDryRunOnMissingResource=true
labels:
app.kubernetes.io/name: cluster-ca-dynamic-fact
name: cluster-ca-dynamic-fact
namespace: syn-cluster-api
spec:
applyOptions:
force: true
context:
- name: source
resource:
apiVersion: v1
kind: Secret
name: c-green-test-1234-ca
serviceAccountRef:
name: cluster-ca-dynamic-fact-manager
template: |
local esp = import 'espejote.libsonnet';
local src =
local srcs = esp.context().source;
assert std.length(srcs) == 1 : 'Expected source context to have length 1';
srcs[0];
{
apiVersion: 'v1',
kind: 'ConfigMap',
metadata: {
name: 'capi-ca-fact',
namespace: 'syn',
labels: {
'app.kubernetes.io/managed-by': 'espejote',
'steward.syn.tools/include-facts': '',
},
},
data: {
facts: std.manifestJsonMinified({
talosAPICertificateAuthorityData: src.data['tls.crt'],
}),
},
}
triggers:
- name: source
watchContextResource:
name: source
- name: target
watchResource:
apiVersion: v1
kind: ConfigMap
name: capi-ca-fact
namespace: syn
Loading