mirror of
https://github.com/cirruslabs/orchard.git
synced 2026-10-09 00:11:37 +02:00
Simplified bootstrapping of a cluster (#40)
* Simplified bootstrapping of a cluster Introduced a new convention about a pre-defined `bootstrap-admin` account for `orchard controller run`. Providing `ORCHARD_BOOTSTRAP_ADMIN_TOKEN` will auto-create such user for easier configuration. `bootstrap-admin` can be used for creating other service accounts on the first run and after that can be disposed. Also change `orchard worker run` to expect controller URL as the only parameter and a bootstrap token passed via an argument instead of using a context that might not be created. * Missing error check
This commit is contained in:
@@ -20,8 +20,6 @@ var ErrInitFailed = errors.New("controller initialization failed")
|
||||
|
||||
var controllerCertPath string
|
||||
var controllerKeyPath string
|
||||
var serviceAccountName string
|
||||
var serviceAccountToken string
|
||||
|
||||
func FindControllerCertificate(dataDir *controller.DataDir) (controllerCert tls.Certificate, err error) {
|
||||
if controllerCertPath != "" || controllerKeyPath != "" {
|
||||
|
||||
@@ -14,6 +14,7 @@ import (
|
||||
)
|
||||
|
||||
var ErrRunFailed = errors.New("failed to run controller")
|
||||
var BootstrapAdminAccountName = "bootstrap-admin"
|
||||
|
||||
var address string
|
||||
|
||||
@@ -39,11 +40,6 @@ func newRunCommand() *cobra.Command {
|
||||
cmd.PersistentFlags().StringVar(&controllerKeyPath, "controller-key", "",
|
||||
"use the controller certificate key from the specified path instead of the auto-generated one"+
|
||||
" (requires --controller-cert)")
|
||||
cmd.PersistentFlags().StringVar(&serviceAccountName, "superuser-account-name", "",
|
||||
"optional name of a service account with maximum privileges to auto-create")
|
||||
cmd.PersistentFlags().StringVar(&serviceAccountToken, "superuser-account-token", "",
|
||||
"token to use when creating a service account with maximum privileges "+
|
||||
"(required when --admin-account-name is specified)")
|
||||
|
||||
return cmd
|
||||
}
|
||||
@@ -94,14 +90,19 @@ func runController(cmd *cobra.Command, args []string) (err error) {
|
||||
return err
|
||||
}
|
||||
|
||||
if serviceAccountName != "" {
|
||||
if adminToken, ok := os.LookupEnv("ORCHARD_BOOTSTRAP_ADMIN_TOKEN"); ok {
|
||||
err = controllerInstance.EnsureServiceAccount(&v1.ServiceAccount{
|
||||
Meta: v1.Meta{
|
||||
Name: serviceAccountName,
|
||||
Name: BootstrapAdminAccountName,
|
||||
},
|
||||
Token: serviceAccountToken,
|
||||
Token: adminToken,
|
||||
Roles: v1.AllServiceAccountRoles(),
|
||||
})
|
||||
} else {
|
||||
err = controllerInstance.DeleteServiceAccount(BootstrapAdminAccountName)
|
||||
}
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
return controllerInstance.Run(cmd.Context())
|
||||
|
||||
Reference in New Issue
Block a user