Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
68 commits
Select commit Hold shift + click to select a range
5eb50d8
Update values.yaml
xiangjingli Apr 26, 2024
5c61202
Merge branch 'open-cluster-management-io:main' into main
xiangjingli Jun 5, 2024
fe443c5
Merge branch 'open-cluster-management-io:main' into main
xiangjingli Jun 10, 2024
5375ad0
added ocpVersion to values.yaml
dislbenn Oct 21, 2024
e45ed24
Merge pull request #11 from dislbenn/add-ocp-version-to-chart
xiangjingli Oct 21, 2024
32ff2cf
Merge branch 'open-cluster-management-io:main' into main
xiangjingli Jan 7, 2025
b356967
update konflux reference
xiangjingli Jan 9, 2025
0ed296a
Merge branch 'open-cluster-management-io:main' into main
mikeshng Mar 21, 2025
6daeee3
Merge branch 'open-cluster-management-io:main' into main
mikeshng Mar 21, 2025
8374227
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Mar 25, 2025
6047f27
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Mar 31, 2025
17cf2a5
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Apr 1, 2025
7d17c81
[main] Red Hat Konflux update cluster-permission-acm-214 (#73)
openshift-cherrypick-robot Apr 10, 2025
8b6b4c4
chore(deps): update konflux references (#43)
red-hat-konflux[bot] Apr 11, 2025
ec397e1
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Apr 15, 2025
e7f5123
ACM-19998 Disable Konflux Go dependency updates (#101)
fxiang1 Apr 15, 2025
978a990
chore(deps): update konflux references (#74)
red-hat-konflux[bot] Apr 17, 2025
86f11a2
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Apr 30, 2025
d7ed105
Sync release-2.14 to main
fxiang1 May 8, 2025
25c64e3
Merge pull request #110 from fxiang1/feng-syncmain
fxiang1 May 8, 2025
957301a
chore(deps): update konflux references (#111)
red-hat-konflux[bot] May 14, 2025
db08727
chore(deps): update konflux references (#114)
red-hat-konflux[bot] May 21, 2025
3b0cf3d
chore(deps): update konflux references
red-hat-konflux[bot] May 24, 2025
1fcd6c8
Merge branch 'open-cluster-management-io:main' into main
fxiang1 May 29, 2025
3f78297
Merge pull request #115 from stolostron/konflux/references/release-2.14
fxiang1 May 30, 2025
89cbb1b
chore(deps): update konflux references (#116)
red-hat-konflux[bot] Jun 2, 2025
1d92f5d
Add multi-arch Konflux build (#117)
dhaiducek Jun 6, 2025
9a1fd55
chore(deps): update konflux references (#120)
red-hat-konflux[bot] Jun 9, 2025
d6423a4
chore(deps): update konflux references (#121)
red-hat-konflux[bot] Jun 17, 2025
2aff6f9
Red Hat Konflux update cluster-permission-acm-215 (#132)
red-hat-konflux[bot] Jul 11, 2025
8384c33
chore(deps): update konflux references (#134)
red-hat-konflux[bot] Jul 15, 2025
e704986
chore(deps): update quay.io/konflux-ci/konflux-vanguard/task-rpms-sig…
red-hat-konflux[bot] Jul 16, 2025
b2ec934
Red Hat Konflux update cluster-permission-acm-215 (#138)
red-hat-konflux[bot] Jul 17, 2025
0c70c83
chore(deps): update konflux references (#143)
red-hat-konflux[bot] Jul 21, 2025
08444a9
chore(deps): update quay.io/konflux-ci/konflux-vanguard/task-rpms-sig…
red-hat-konflux[bot] Jul 22, 2025
5445b62
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Aug 7, 2025
43d8ede
chore(deps): update quay.io/konflux-ci/konflux-vanguard/task-rpms-sig…
red-hat-konflux[bot] Aug 9, 2025
a2034b8
chore(deps): update konflux references (#145)
red-hat-konflux[bot] Aug 12, 2025
798b1aa
Merge pull request #146 from stolostron/konflux/mintmaker/release-2.1…
fxiang1 Aug 13, 2025
a3dcc78
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Aug 25, 2025
ff46dfb
chore(deps): update konflux references (#148)
red-hat-konflux[bot] Aug 25, 2025
c757238
chore(deps): update quay.io/konflux-ci/konflux-vanguard/task-rpms-sig…
red-hat-konflux[bot] Aug 25, 2025
5307832
chore(deps): update konflux references (#152)
red-hat-konflux[bot] Sep 3, 2025
86be2d1
Add CLAUDE.md documentation
jhjaggars Sep 18, 2025
e04f080
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Sep 19, 2025
e616a6b
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Sep 24, 2025
230d6c5
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Sep 26, 2025
20e5fcd
Merge pull request #155 from jhjaggars/add-claude-md
fxiang1 Sep 26, 2025
77c0949
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Oct 3, 2025
91bda48
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Oct 7, 2025
fef009f
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Oct 20, 2025
b71c383
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Oct 22, 2025
1dbeda9
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Oct 22, 2025
ce41e10
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Oct 27, 2025
07fdaca
Red Hat Konflux update cluster-permission-acm-216 (#162)
red-hat-konflux[bot] Nov 12, 2025
b2253aa
Merge branch 'open-cluster-management-io:main' into main
fxiang1 Nov 26, 2025
cbad5e7
Merge branch 'open-cluster-management-io:main' into main
elgnay Dec 12, 2025
98e70b5
Merge branch 'open-cluster-management-io:main' into main
zhiweiyin318 Dec 17, 2025
d64d95a
Merge branch 'open-cluster-management-io:main' into main
zhiweiyin318 Dec 23, 2025
761d306
Update Dockerfile.rhtap labels with correct name and cpe values (#177)
xuezhaojun Jan 21, 2026
e00ce2a
Merge branch 'open-cluster-management-io:main' into main
haoqing0110 Jan 27, 2026
38a8d98
Update renovate.json to use team shared configuration (#182)
xuezhaojun Jan 30, 2026
722957d
:seedling: [main] update konflux files (#194)
zhujian7 Feb 6, 2026
99bf158
Red Hat Konflux update cluster-permission-acm-217 (#195)
red-hat-konflux[bot] Feb 6, 2026
25f12b7
:seedling: [main] update konflux files (#196)
zhujian7 Feb 6, 2026
97deb24
Merge branch 'open-cluster-management-io:main' into main
xuezhaojun Mar 12, 2026
c6b8e95
feat: migrate cluster-permission from ACM to MCE build (#207)
xuezhaojun Mar 19, 2026
4ad119b
docs: unify README.md and CLAUDE.md via symlink
Mar 20, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions .tekton/OWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
approvers:
- zhujian7
- zhiweiyin318
- haoqing0110
- elgnay
- xuezhaojun
- qiujian16

reviewers:
- zhujian7
- zhiweiyin318
- haoqing0110
- elgnay
- xuezhaojun
- qiujian16
56 changes: 56 additions & 0 deletions .tekton/cluster-permission-mce-217-pull-request.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
apiVersion: tekton.dev/v1
kind: PipelineRun
metadata:
annotations:
build.appstudio.openshift.io/repo: https://github.com/stolostron/cluster-permission?rev={{revision}}
build.appstudio.redhat.com/commit_sha: '{{revision}}'
build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}'
build.appstudio.redhat.com/target_branch: '{{target_branch}}'
pipelinesascode.tekton.dev/cancel-in-progress: "true"
pipelinesascode.tekton.dev/max-keep-runs: "3"
pipelinesascode.tekton.dev/on-cel-expression: event == "pull_request" && target_branch == "main"
creationTimestamp:
labels:
appstudio.openshift.io/application: release-mce-217
appstudio.openshift.io/component: cluster-permission-mce-217
pipelines.appstudio.openshift.io/type: build
name: cluster-permission-mce-217-on-pull-request
namespace: crt-redhat-acm-tenant
spec:
params:
- name: git-url
value: '{{source_url}}'
- name: revision
value: '{{revision}}'
- name: output-image
value: quay.io/redhat-user-workloads/crt-redhat-acm-tenant/cluster-permission-mce-217:on-pr-{{revision}}
- name: image-expires-after
value: 5d
- name: build-platforms
value:
- linux/x86_64
- linux/arm64
- linux/ppc64le
- linux/s390x
- name: dockerfile
value: Dockerfile.rhtap
- name: path-context
value: .
- name: prefetch-input
value: '[{"type": "gomod", "path": "."}, {"type": "rpm", "path": "."}]'
pipelineRef:
resolver: git
params:
- name: url
value: https://github.com/stolostron/konflux-build-catalog.git
- name: revision
value: main
- name: pathInRepo
value: pipelines/common.yaml
taskRunTemplate:
serviceAccountName: build-pipeline-cluster-permission-mce-217
workspaces:
- name: git-auth
secret:
secretName: '{{ git_auth_secret }}'
status: {}
59 changes: 59 additions & 0 deletions .tekton/cluster-permission-mce-217-push.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
apiVersion: tekton.dev/v1
kind: PipelineRun
metadata:
annotations:
build.appstudio.openshift.io/repo: https://github.com/stolostron/cluster-permission?rev={{revision}}
build.appstudio.redhat.com/commit_sha: '{{revision}}'
build.appstudio.redhat.com/target_branch: '{{target_branch}}'
pipelinesascode.tekton.dev/cancel-in-progress: "false"
pipelinesascode.tekton.dev/max-keep-runs: "3"
pipelinesascode.tekton.dev/on-cel-expression: event == "push" && target_branch == "main"
creationTimestamp:
labels:
appstudio.openshift.io/application: release-mce-217
appstudio.openshift.io/component: cluster-permission-mce-217
pipelines.appstudio.openshift.io/type: build
name: cluster-permission-mce-217-on-push
namespace: crt-redhat-acm-tenant
spec:
params:
- name: git-url
value: '{{source_url}}'
- name: revision
value: '{{revision}}'
- name: output-image
value: quay.io/redhat-user-workloads/crt-redhat-acm-tenant/cluster-permission-mce-217:{{revision}}
- name: build-platforms
value:
- linux/x86_64
- linux/arm64
- linux/ppc64le
- linux/s390x
- name: dockerfile
value: Dockerfile.rhtap
- name: path-context
value: .
- name: send-slack-notification
value: 'true'
- name: konflux-application-name
value: release-mce-217
- name: slack-member-id
value: UUSRGGQ1L
- name: prefetch-input
value: '[{"type": "gomod", "path": "."}, {"type": "rpm", "path": "."}]'
pipelineRef:
resolver: git
params:
- name: url
value: https://github.com/stolostron/konflux-build-catalog.git
- name: revision
value: main
- name: pathInRepo
value: pipelines/common.yaml
taskRunTemplate:
serviceAccountName: build-pipeline-cluster-permission-mce-217
workspaces:
- name: git-auth
secret:
secretName: '{{ git_auth_secret }}'
status: {}
1 change: 1 addition & 0 deletions AGENTS.md
1 change: 1 addition & 0 deletions CLAUDE.md
13 changes: 13 additions & 0 deletions Dockerfile.rhtap
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,19 @@ ENV OPERATOR=/usr/local/bin/cluster-permission \
USER_UID=1001 \
USER_NAME=cluster-permission

LABEL \
name="multicluster-engine/cluster-permission-rhel9" \
com.redhat.component="cluster-permission" \
cpe="cpe:/a:redhat:multicluster_engine:2.11::el9" \
description="Cluster permission controller" \
maintainer="acm-contact@redhat.com" \
io.k8s.description="Cluster permission controller" \
org.label-schema.license="Red Hat Advanced Cluster Management for Kubernetes EULA" \
org.label-schema.schema-version="1.0" \
summary="Cluster permission controller" \
io.k8s.display-name="Cluster permission" \
io.openshift.tags="mce acm cluster-permission"

# install operator binary
COPY --from=plugin-builder /go/src/github.com/open-cluster-management-io/cluster-permission/bin/cluster-permission /usr/local/bin/cluster-permission

Expand Down
69 changes: 60 additions & 9 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -200,33 +200,84 @@ kubectl logs -n cluster-permission-system deployment/cluster-permission-controll

## Development

### Building from Source
### Building and Testing

```bash
# Install CRDs to cluster
make install

# Run controller locally (requires access to OCM hub cluster)
make run

# Build the binary
make build

# Build Docker image
make docker-build

# Run tests
make test

# Generate CRDs
make manifests
# Run end-to-end tests (deploys OCM first)
make test-e2e

# Update generated code
make generate
# Build Docker image
make docker-build

# Deploy to cluster
make deploy

# Remove from cluster
make undeploy
```

### Code Generation

After modifying API types, regenerate code:
```bash
make generate
# Generate manifests (CRDs, RBAC, etc.)
make manifests

# Generate deepcopy methods and client code
make generate

# Combined pre-build tasks (deps, manifests, generate, fmt, vet)
make pre-build
```

### Dependencies and Linting

```bash
# Update Go dependencies
make deps

# Format code
make fmt

# Run go vet
make vet
```

### Testing Framework

- Uses Ginkgo/Gomega for testing
- Controller tests in `controllers/clusterpermission_controller_test.go`
- Test suite setup in `controllers/suite_test.go`
- E2E tests in `e2e/` directory
- Tests require OCM environment for full functionality

### Code Structure

- **API Types** (`api/v1alpha1/`): Follow Kubernetes API conventions with `+optional` markers. Condition types defined as constants.
- **Controller** (`controllers/`): Standard controller-runtime reconciler pattern. Uses ManifestWork to deploy RBAC to managed clusters. Status conditions track reconciliation state.
- **Generated Client** (`client/`): Auto-generated Kubernetes client code. Update with `make generate` after API changes.
- **Configuration** (`config/`): Kubernetes manifests for CRDs, RBAC, and deployment.

### Important Files

- `main.go`: Controller manager entry point with scheme registration
- `api/v1alpha1/clusterpermission_types.go`: Core API types and specifications
- `controllers/clusterpermission_controller.go`: Main reconciliation logic
- `controllers/helper.go`: Utility functions for manifest generation
- `config/samples/`: Example ClusterPermission resources for testing

## Community and Support

### Contributing
Expand Down
1 change: 1 addition & 0 deletions chart/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ global:
pullSecret: null
hubconfig:
nodeSelector: null
ocpVersion: 4.12.0
proxyConfigs: {}
replicaCount: 1
tolerations: []
Expand Down
4 changes: 4 additions & 0 deletions renovate.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": ["github>stolostron/acm-config//teams/server-foundation/renovate-with-upstream.json"]
}
19 changes: 19 additions & 0 deletions rpms.in.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
contentOrigin:
repos:
- repoid: ubi-9-for-${basearch}-baseos-rpms
baseurl: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/${basearch}/baseos/os/
- repoid: ubi-9-for-${basearch}-appstream-rpms
baseurl: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/${basearch}/appstream/os/
packages:
- jq
- tar
- gzip
- rsync
- findutils
context:
containerfile: Dockerfile.rhtap
arches:
- aarch64
- x86_64
- s390x
- ppc64le
Loading
Loading