mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 17:28:26 +00:00
feat(k8-operator): push secrets
This commit is contained in:
@@ -191,74 +191,239 @@ spec:
|
|||||||
`json:\"conditions,omitempty\" patchStrategy:\"merge\" patchMergeKey:\"type\"
|
`json:\"conditions,omitempty\" patchStrategy:\"merge\" patchMergeKey:\"type\"
|
||||||
protobuf:\"bytes,1,rep,name=conditions\"` \n // other fields }"
|
protobuf:\"bytes,1,rep,name=conditions\"` \n // other fields }"
|
||||||
properties:
|
properties:
|
||||||
lastTransitionTime:
|
awsIamAuth:
|
||||||
description: lastTransitionTime is the last time the condition
|
properties:
|
||||||
transitioned from one status to another. This should be when
|
identityId:
|
||||||
the underlying condition changed. If that is not known, then
|
type: string
|
||||||
using the time when the API field changed is acceptable.
|
required:
|
||||||
format: date-time
|
- identityId
|
||||||
|
type: object
|
||||||
|
azureAuth:
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
resource:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
type: object
|
||||||
|
gcpIamAuth:
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
serviceAccountKeyFilePath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
- serviceAccountKeyFilePath
|
||||||
|
type: object
|
||||||
|
gcpIdTokenAuth:
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
type: object
|
||||||
|
kubernetesAuth:
|
||||||
|
description: Rest of your types should be defined similarly...
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
serviceAccountRef:
|
||||||
|
properties:
|
||||||
|
name:
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
- serviceAccountRef
|
||||||
|
type: object
|
||||||
|
universalAuth:
|
||||||
|
description: PushSecretUniversalAuth defines universal authentication
|
||||||
|
properties:
|
||||||
|
credentialsRef:
|
||||||
|
properties:
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description:
|
||||||
|
The name space where the Kubernetes Secret
|
||||||
|
is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- credentialsRef
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
deletionPolicy:
|
||||||
|
type: string
|
||||||
|
destination:
|
||||||
|
properties:
|
||||||
|
EnvironmentSlug:
|
||||||
type: string
|
type: string
|
||||||
message:
|
projectId:
|
||||||
description: message is a human readable message indicating
|
|
||||||
details about the transition. This may be an empty string.
|
|
||||||
maxLength: 32768
|
|
||||||
type: string
|
type: string
|
||||||
observedGeneration:
|
secretsPath:
|
||||||
description: observedGeneration represents the .metadata.generation
|
|
||||||
that the condition was set based upon. For instance, if .metadata.generation
|
|
||||||
is currently 12, but the .status.conditions[x].observedGeneration
|
|
||||||
is 9, the condition is out of date with respect to the current
|
|
||||||
state of the instance.
|
|
||||||
format: int64
|
|
||||||
minimum: 0
|
|
||||||
type: integer
|
|
||||||
reason:
|
|
||||||
description: reason contains a programmatic identifier indicating
|
|
||||||
the reason for the condition's last transition. Producers
|
|
||||||
of specific condition types may define expected values and
|
|
||||||
meanings for this field, and whether the values are considered
|
|
||||||
a guaranteed API. The value should be a CamelCase string.
|
|
||||||
This field may not be empty.
|
|
||||||
maxLength: 1024
|
|
||||||
minLength: 1
|
|
||||||
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
|
|
||||||
type: string
|
|
||||||
status:
|
|
||||||
description: status of the condition, one of True, False, Unknown.
|
|
||||||
enum:
|
|
||||||
- "True"
|
|
||||||
- "False"
|
|
||||||
- Unknown
|
|
||||||
type: string
|
|
||||||
type:
|
|
||||||
description: type of condition in CamelCase or in foo.example.com/CamelCase.
|
|
||||||
--- Many .condition.type values are consistent across resources
|
|
||||||
like Available, but because arbitrary conditions can be useful
|
|
||||||
(see .node.status.conditions), the ability to deconflict is
|
|
||||||
important. The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
|
|
||||||
maxLength: 316
|
|
||||||
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
|
|
||||||
type: string
|
type: string
|
||||||
required:
|
required:
|
||||||
- lastTransitionTime
|
- EnvironmentSlug
|
||||||
- message
|
- projectId
|
||||||
- reason
|
- secretsPath
|
||||||
- status
|
|
||||||
- type
|
|
||||||
type: object
|
type: object
|
||||||
type: array
|
hostAPI:
|
||||||
managedSecrets:
|
description: Infisical host to pull secrets from
|
||||||
additionalProperties:
|
|
||||||
type: string
|
type: string
|
||||||
description: managed secrets is a map where the key is the ID, and
|
push:
|
||||||
the value is the secret key (string[id], string[key] )
|
properties:
|
||||||
type: object
|
secret:
|
||||||
required:
|
properties:
|
||||||
- conditions
|
secretName:
|
||||||
- managedSecrets
|
description: The name of the Kubernetes Secret
|
||||||
type: object
|
type: string
|
||||||
type: object
|
secretNamespace:
|
||||||
served: true
|
description:
|
||||||
storage: true
|
The name space where the Kubernetes Secret is
|
||||||
subresources:
|
located
|
||||||
status: {}
|
type: string
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- secret
|
||||||
|
type: object
|
||||||
|
resyncInterval:
|
||||||
|
type: string
|
||||||
|
tls:
|
||||||
|
properties:
|
||||||
|
caRef:
|
||||||
|
description: Reference to secret containing CA cert
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description:
|
||||||
|
The name of the secret property with the CA certificate
|
||||||
|
value
|
||||||
|
type: string
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description:
|
||||||
|
The namespace where the Kubernetes Secret is
|
||||||
|
located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
updatePolicy:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- destination
|
||||||
|
- push
|
||||||
|
- resyncInterval
|
||||||
|
type: object
|
||||||
|
status:
|
||||||
|
description: InfisicalPushSecretStatus defines the observed state of InfisicalPushSecret
|
||||||
|
properties:
|
||||||
|
conditions:
|
||||||
|
items:
|
||||||
|
description:
|
||||||
|
"Condition contains details for one aspect of the current
|
||||||
|
state of this API Resource. --- This struct is intended for direct
|
||||||
|
use as an array at the field path .status.conditions. For example,
|
||||||
|
\n type FooStatus struct{ // Represents the observations of a
|
||||||
|
foo's current state. // Known .status.conditions.type are: \"Available\",
|
||||||
|
\"Progressing\", and \"Degraded\" // +patchMergeKey=type // +patchStrategy=merge
|
||||||
|
// +listType=map // +listMapKey=type Conditions []metav1.Condition
|
||||||
|
`json:\"conditions,omitempty\" patchStrategy:\"merge\" patchMergeKey:\"type\"
|
||||||
|
protobuf:\"bytes,1,rep,name=conditions\"` \n // other fields }"
|
||||||
|
properties:
|
||||||
|
lastTransitionTime:
|
||||||
|
description:
|
||||||
|
lastTransitionTime is the last time the condition
|
||||||
|
transitioned from one status to another. This should be when
|
||||||
|
the underlying condition changed. If that is not known, then
|
||||||
|
using the time when the API field changed is acceptable.
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
message:
|
||||||
|
description:
|
||||||
|
message is a human readable message indicating
|
||||||
|
details about the transition. This may be an empty string.
|
||||||
|
maxLength: 32768
|
||||||
|
type: string
|
||||||
|
observedGeneration:
|
||||||
|
description:
|
||||||
|
observedGeneration represents the .metadata.generation
|
||||||
|
that the condition was set based upon. For instance, if .metadata.generation
|
||||||
|
is currently 12, but the .status.conditions[x].observedGeneration
|
||||||
|
is 9, the condition is out of date with respect to the current
|
||||||
|
state of the instance.
|
||||||
|
format: int64
|
||||||
|
minimum: 0
|
||||||
|
type: integer
|
||||||
|
reason:
|
||||||
|
description:
|
||||||
|
reason contains a programmatic identifier indicating
|
||||||
|
the reason for the condition's last transition. Producers
|
||||||
|
of specific condition types may define expected values and
|
||||||
|
meanings for this field, and whether the values are considered
|
||||||
|
a guaranteed API. The value should be a CamelCase string.
|
||||||
|
This field may not be empty.
|
||||||
|
maxLength: 1024
|
||||||
|
minLength: 1
|
||||||
|
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
|
||||||
|
type: string
|
||||||
|
status:
|
||||||
|
description: status of the condition, one of True, False, Unknown.
|
||||||
|
enum:
|
||||||
|
- "True"
|
||||||
|
- "False"
|
||||||
|
- Unknown
|
||||||
|
type: string
|
||||||
|
type:
|
||||||
|
description:
|
||||||
|
type of condition in CamelCase or in foo.example.com/CamelCase.
|
||||||
|
--- Many .condition.type values are consistent across resources
|
||||||
|
like Available, but because arbitrary conditions can be useful
|
||||||
|
(see .node.status.conditions), the ability to deconflict is
|
||||||
|
important. The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
|
||||||
|
maxLength: 316
|
||||||
|
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- lastTransitionTime
|
||||||
|
- message
|
||||||
|
- reason
|
||||||
|
- status
|
||||||
|
- type
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
managedSecrets:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description:
|
||||||
|
managed secrets is a map where the key is the ID, and
|
||||||
|
the value is the secret key (string[id], string[key] )
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- conditions
|
||||||
|
- managedSecrets
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
|||||||
@@ -35,6 +35,8 @@ func (r *InfisicalSecretReconciler) GetLogger(req ctrl.Request) logr.Logger {
|
|||||||
return r.BaseLogger.WithValues("infisicalsecret", req.NamespacedName)
|
return r.BaseLogger.WithValues("infisicalsecret", req.NamespacedName)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
var resourceVariablesMap map[string]util.ResourceVariables = make(map[string]util.ResourceVariables)
|
||||||
|
|
||||||
//+kubebuilder:rbac:groups=secrets.infisical.com,resources=infisicalsecrets,verbs=get;list;watch;create;update;patch;delete
|
//+kubebuilder:rbac:groups=secrets.infisical.com,resources=infisicalsecrets,verbs=get;list;watch;create;update;patch;delete
|
||||||
//+kubebuilder:rbac:groups=secrets.infisical.com,resources=infisicalsecrets/status,verbs=get;update;patch
|
//+kubebuilder:rbac:groups=secrets.infisical.com,resources=infisicalsecrets/status,verbs=get;update;patch
|
||||||
//+kubebuilder:rbac:groups=secrets.infisical.com,resources=infisicalsecrets/finalizers,verbs=update
|
//+kubebuilder:rbac:groups=secrets.infisical.com,resources=infisicalsecrets/finalizers,verbs=update
|
||||||
|
|||||||
Reference in New Issue
Block a user