forked from open-cluster-management-io/cluster-permission
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathclusterpermission_types.go
More file actions
180 lines (145 loc) · 7.04 KB
/
Copy pathclusterpermission_types.go
File metadata and controls
180 lines (145 loc) · 7.04 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
/*
Copyright 2023.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/
package v1alpha1
import (
rbacv1 "k8s.io/api/rbac/v1"
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
)
const (
ConditionTypeAppliedRBACManifestWork string = "AppliedRBACManifestWork"
ConditionTypeValidation string = "Validation"
)
// ClusterPermissionSpec defines the desired state of ClusterPermission
type ClusterPermissionSpec struct {
// ClusterRole represents the ClusterRole that is being created on the managed cluster
// +optional
ClusterRole *ClusterRole `json:"clusterRole,omitempty"`
// ClusterRoleBinding represents the ClusterRoleBinding that is being created on the managed cluster
// +optional
// +kubebuilder:validation:XValidation:rule="has(self.subject) || has(self.subjects)",message="Either subject or subjects has to exist in clusterRoleBinding"
ClusterRoleBinding *ClusterRoleBinding `json:"clusterRoleBinding,omitempty"`
// ClusterRoleBindings represents multiple ClusterRoleBindings that are being created on the managed cluster
// +optional
// +kubebuilder:validation:XValidation:rule="self.all(i, has(i.subject) || has(i.subjects))",message="Either subject or subjects has to exist in every clusterRoleBinding"
ClusterRoleBindings *[]ClusterRoleBinding `json:"clusterRoleBindings,omitempty"`
// Roles represents roles that are being created on the managed cluster
// +optional
Roles *[]Role `json:"roles,omitempty"`
// RoleBindings represents RoleBindings that are being created on the managed cluster
// +optional
// +kubebuilder:validation:XValidation:rule="self.all(i, has(i.subject) || has(i.subjects))",message="Either subject or subjects has to exist in every roleBinding"
RoleBindings *[]RoleBinding `json:"roleBindings,omitempty"`
}
// ClusterRole represents the ClusterRole that is being created on the managed cluster
type ClusterRole struct {
// Rules holds all the PolicyRules for this ClusterRole
// +required
Rules []rbacv1.PolicyRule `json:"rules"`
}
// ClusterRoleBinding represents the ClusterRoleBinding that is being created on the managed cluster
type ClusterRoleBinding struct {
// Subject contains a reference to the object or user identities a ClusterPermission binding applies to.
// Besides the typical subject for a binding, a ManagedServiceAccount can be used as a subject as well.
// If both subject and subjects exist then only subjects will be used.
// +optional
Subject rbacv1.Subject `json:"subject"`
// Subjects contains an array of references to objects or user identities a ClusterPermission binding applies to.
// Besides the typical subject for a binding, a ManagedServiceAccount can be used as a subject as well.
// If both subject and subjects exist then only subjects will be used.
// +optional
Subjects []rbacv1.Subject `json:"subjects"`
// Name of the ClusterRoleBinding if a name different than the ClusterPermission name is used
// +optional
Name string `json:"name,omitempty" protobuf:"bytes,4,opt,name=name"`
// RoleRef contains information that points to the ClusterRole being used
// +optional
RoleRef *rbacv1.RoleRef `json:"roleRef,omitempty"`
}
// Role represents the Role that is being created on the managed cluster
type Role struct {
// Namespace of the Role for that is being created on the managed cluster
// +optional
Namespace string `json:"namespace,omitempty" protobuf:"bytes,4,opt,name=namespace"`
// NamespaceSelector define the general labelSelector which namespace to apply the rules to
// Note: the namespace must exists on the hub cluster
// +optional
NamespaceSelector *metav1.LabelSelector `json:"namespaceSelector,omitempty"`
// Rules holds all the PolicyRules for this Role
// +required
Rules []rbacv1.PolicyRule `json:"rules"`
}
// RoleBinding represents the RoleBinding that is being created on the managed cluster
type RoleBinding struct {
// Subject contains a reference to the object or user identities a ClusterPermission binding applies to.
// Besides the typical subject for a binding, a ManagedServiceAccount can be used as a subject as well.
// If both subject and subjects exist then only subjects will be used.
// +optional
rbacv1.Subject `json:"subject"`
// Subjects contains an array of references to objects or user identities a ClusterPermission binding applies to.
// Besides the typical subject for a binding, a ManagedServiceAccount can be used as a subject as well.
// If both subject and subjects exist then only subjects will be used.
// +optional
Subjects []rbacv1.Subject `json:"subjects"`
// RoleRef contains information that points to the role being used
// +required
RoleRef `json:"roleRef"`
// Namespace of the Role for that is being created on the managed cluster
// +optional
Namespace string `json:"namespace,omitempty" protobuf:"bytes,4,opt,name=namespace"`
// NamespaceSelector define the general labelSelector which namespace to apply the rules to
// Note: the namespace must exists on the hub cluster
// +optional
NamespaceSelector *metav1.LabelSelector `json:"namespaceSelector,omitempty"`
// Name of the RoleBinding if a name different than the ClusterPermission name is used
// +optional
Name string `json:"name,omitempty" protobuf:"bytes,4,opt,name=name"`
}
// RoleRef contains information that points to the role being used
type RoleRef struct {
// Kind is the type of resource being referenced
// +required
Kind string `json:"kind"`
// APIGroup is the group for the resource being referenced
// +optional
APIGroup string `json:"apiGroup" protobuf:"bytes,1,opt,name=apiGroup"`
// Name is the name of resource being referenced
// +optional
Name string `json:"name" protobuf:"bytes,3,opt,name=name"`
}
// ClusterPermissionStatus defines the observed state of ClusterPermission
type ClusterPermissionStatus struct {
// Conditions is the condition list.
// +optional
Conditions []metav1.Condition `json:"conditions,omitempty"`
}
//+genclient
//+kubebuilder:object:root=true
//+kubebuilder:subresource:status
//+kubebuilder:resource:scope=Namespaced
// ClusterPermission is the Schema for the clusterpermissions API
type ClusterPermission struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
Spec ClusterPermissionSpec `json:"spec,omitempty"`
Status ClusterPermissionStatus `json:"status,omitempty"`
}
//+kubebuilder:object:root=true
// ClusterPermissionList contains a list of ClusterPermission
type ClusterPermissionList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []ClusterPermission `json:"items"`
}
func init() {
SchemeBuilder.Register(&ClusterPermission{}, &ClusterPermissionList{})
}