feat(k8s): automatic service account token creation for k8s auth

This commit is contained in:
Daniel Hougaard
2025-04-01 23:39:22 +04:00
parent 82b828c10e
commit 3d072c2f48
5 changed files with 73 additions and 5 deletions
@@ -48,7 +48,7 @@ func (in *Authentication) DeepCopyInto(out *Authentication) {
out.ServiceAccount = in.ServiceAccount out.ServiceAccount = in.ServiceAccount
out.ServiceToken = in.ServiceToken out.ServiceToken = in.ServiceToken
out.UniversalAuth = in.UniversalAuth out.UniversalAuth = in.UniversalAuth
out.KubernetesAuth = in.KubernetesAuth in.KubernetesAuth.DeepCopyInto(&out.KubernetesAuth)
out.AwsIamAuth = in.AwsIamAuth out.AwsIamAuth = in.AwsIamAuth
out.AzureAuth = in.AzureAuth out.AzureAuth = in.AzureAuth
out.GcpIdTokenAuth = in.GcpIdTokenAuth out.GcpIdTokenAuth = in.GcpIdTokenAuth
@@ -207,7 +207,7 @@ func (in *GenericGcpIdTokenAuth) DeepCopy() *GenericGcpIdTokenAuth {
func (in *GenericInfisicalAuthentication) DeepCopyInto(out *GenericInfisicalAuthentication) { func (in *GenericInfisicalAuthentication) DeepCopyInto(out *GenericInfisicalAuthentication) {
*out = *in *out = *in
out.UniversalAuth = in.UniversalAuth out.UniversalAuth = in.UniversalAuth
out.KubernetesAuth = in.KubernetesAuth in.KubernetesAuth.DeepCopyInto(&out.KubernetesAuth)
out.AwsIamAuth = in.AwsIamAuth out.AwsIamAuth = in.AwsIamAuth
out.AzureAuth = in.AzureAuth out.AzureAuth = in.AzureAuth
out.GcpIdTokenAuth = in.GcpIdTokenAuth out.GcpIdTokenAuth = in.GcpIdTokenAuth
@@ -228,6 +228,11 @@ func (in *GenericInfisicalAuthentication) DeepCopy() *GenericInfisicalAuthentica
func (in *GenericKubernetesAuth) DeepCopyInto(out *GenericKubernetesAuth) { func (in *GenericKubernetesAuth) DeepCopyInto(out *GenericKubernetesAuth) {
*out = *in *out = *in
out.ServiceAccountRef = in.ServiceAccountRef out.ServiceAccountRef = in.ServiceAccountRef
if in.ServiceAccountTokenAudiences != nil {
in, out := &in.ServiceAccountTokenAudiences, &out.ServiceAccountTokenAudiences
*out = make([]string, len(*in))
copy(*out, *in)
}
} }
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new GenericKubernetesAuth. // DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new GenericKubernetesAuth.
@@ -336,7 +341,7 @@ func (in *InfisicalDynamicSecretList) DeepCopyObject() runtime.Object {
func (in *InfisicalDynamicSecretSpec) DeepCopyInto(out *InfisicalDynamicSecretSpec) { func (in *InfisicalDynamicSecretSpec) DeepCopyInto(out *InfisicalDynamicSecretSpec) {
*out = *in *out = *in
in.ManagedSecretReference.DeepCopyInto(&out.ManagedSecretReference) in.ManagedSecretReference.DeepCopyInto(&out.ManagedSecretReference)
out.Authentication = in.Authentication in.Authentication.DeepCopyInto(&out.Authentication)
out.DynamicSecret = in.DynamicSecret out.DynamicSecret = in.DynamicSecret
out.TLS = in.TLS out.TLS = in.TLS
} }
@@ -476,7 +481,7 @@ func (in *InfisicalPushSecretSecretSource) DeepCopy() *InfisicalPushSecretSecret
func (in *InfisicalPushSecretSpec) DeepCopyInto(out *InfisicalPushSecretSpec) { func (in *InfisicalPushSecretSpec) DeepCopyInto(out *InfisicalPushSecretSpec) {
*out = *in *out = *in
out.Destination = in.Destination out.Destination = in.Destination
out.Authentication = in.Authentication in.Authentication.DeepCopyInto(&out.Authentication)
in.Push.DeepCopyInto(&out.Push) in.Push.DeepCopyInto(&out.Push)
out.TLS = in.TLS out.TLS = in.TLS
} }
@@ -583,7 +588,7 @@ func (in *InfisicalSecretList) DeepCopyObject() runtime.Object {
func (in *InfisicalSecretSpec) DeepCopyInto(out *InfisicalSecretSpec) { func (in *InfisicalSecretSpec) DeepCopyInto(out *InfisicalSecretSpec) {
*out = *in *out = *in
out.TokenSecretReference = in.TokenSecretReference out.TokenSecretReference = in.TokenSecretReference
out.Authentication = in.Authentication in.Authentication.DeepCopyInto(&out.Authentication)
in.ManagedSecretReference.DeepCopyInto(&out.ManagedSecretReference) in.ManagedSecretReference.DeepCopyInto(&out.ManagedSecretReference)
if in.ManagedKubeSecretReferences != nil { if in.ManagedKubeSecretReferences != nil {
in, out := &in.ManagedKubeSecretReferences, &out.ManagedKubeSecretReferences in, out := &in.ManagedKubeSecretReferences, &out.ManagedKubeSecretReferences
@@ -654,6 +659,11 @@ func (in *KubernetesAuthDetails) DeepCopyInto(out *KubernetesAuthDetails) {
*out = *in *out = *in
out.ServiceAccountRef = in.ServiceAccountRef out.ServiceAccountRef = in.ServiceAccountRef
out.SecretsScope = in.SecretsScope out.SecretsScope = in.SecretsScope
if in.ServiceAccountTokenAudiences != nil {
in, out := &in.ServiceAccountTokenAudiences, &out.ServiceAccountTokenAudiences
*out = make([]string, len(*in))
copy(*out, *in)
}
} }
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new KubernetesAuthDetails. // DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new KubernetesAuthDetails.
@@ -73,6 +73,12 @@ spec:
type: object type: object
kubernetesAuth: kubernetesAuth:
properties: properties:
autoCreateServiceAccountToken:
description: Optionally automatically create a service account
token for the configured service account. If this is set
to `true`, the operator will automatically create a service
account token for the configured service account.
type: boolean
identityId: identityId:
type: string type: string
serviceAccountRef: serviceAccountRef:
@@ -85,6 +91,13 @@ spec:
- name - name
- namespace - namespace
type: object type: object
serviceAccountTokenAudiences:
description: The audiences to use for the service account
token. This is only relevant if `autoCreateServiceAccountToken`
is true.
items:
type: string
type: array
required: required:
- identityId - identityId
- serviceAccountRef - serviceAccountRef
@@ -73,6 +73,12 @@ spec:
type: object type: object
kubernetesAuth: kubernetesAuth:
properties: properties:
autoCreateServiceAccountToken:
description: Optionally automatically create a service account
token for the configured service account. If this is set
to `true`, the operator will automatically create a service
account token for the configured service account.
type: boolean
identityId: identityId:
type: string type: string
serviceAccountRef: serviceAccountRef:
@@ -85,6 +91,13 @@ spec:
- name - name
- namespace - namespace
type: object type: object
serviceAccountTokenAudiences:
description: The audiences to use for the service account
token. This is only relevant if `autoCreateServiceAccountToken`
is true.
items:
type: string
type: array
required: required:
- identityId - identityId
- serviceAccountRef - serviceAccountRef
@@ -136,6 +136,12 @@ spec:
type: object type: object
kubernetesAuth: kubernetesAuth:
properties: properties:
autoCreateServiceAccountToken:
description: Optionally automatically create a service account
token for the configured service account. If this is set
to `true`, the operator will automatically create a service
account token for the configured service account.
type: boolean
identityId: identityId:
type: string type: string
secretsScope: secretsScope:
@@ -163,6 +169,13 @@ spec:
- name - name
- namespace - namespace
type: object type: object
serviceAccountTokenAudiences:
description: The audiences to use for the service account
token. This is only relevant if `autoCreateServiceAccountToken`
is true.
items:
type: string
type: array
required: required:
- identityId - identityId
- secretsScope - secretsScope
+19
View File
@@ -16,6 +16,13 @@ rules:
- list - list
- update - update
- watch - watch
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- list
- apiGroups: - apiGroups:
- "" - ""
resources: resources:
@@ -35,6 +42,12 @@ rules:
- get - get
- list - list
- watch - watch
- apiGroups:
- ""
resources:
- serviceaccounts/token
verbs:
- create
- apiGroups: - apiGroups:
- apps - apps
resources: resources:
@@ -55,6 +68,12 @@ rules:
- list - list
- update - update
- watch - watch
- apiGroups:
- authentication.k8s.io
resources:
- tokenreviews
verbs:
- create
- apiGroups: - apiGroups:
- secrets.infisical.com - secrets.infisical.com
resources: resources: