Improve infrastructure role definitions (#208)

Enhance definitions of infrastructure roles by allowing membership in multiple roles, role options and per-role configuration to be specified in the infrastructure role configmap, which must have the same name as the infrastructure role secret. See manifests/infrastructure-roles-configmap.yaml for the examples and updated README for the description of different types of database roles supposed by the operator and their purposes.

Change the logic of merging infrastructure roles with the manifest roles when they have the same name, to return the infrastructure role unchanged instead of merging. Previously, we used to propagate flags from the manifest role to the resulting infrastructure one, as there were no way to define flags for the infrastructure role; however, this is not the case anymore.

Code review and tests by @erthalion
This commit is contained in:
Oleksii Kliukin
2018-04-04 17:21:36 +02:00
committed by GitHub
parent d264be9faa
commit 26db91c53e
10 changed files with 261 additions and 51 deletions
+24 -8
View File
@@ -32,12 +32,14 @@ const (
fileWithNamespace = "/var/run/secrets/kubernetes.io/serviceaccount/namespace"
)
// RoleOrigin contains the code of the origin of a role
type RoleOrigin int
// The rolesOrigin constant values should be sorted by the role priority.
const (
RoleOriginUnknown = iota
RoleOriginInfrastructure
RoleOriginUnknown RoleOrigin = iota
RoleOriginManifest
RoleOriginInfrastructure
RoleOriginTeamsAPI
RoleOriginSystem
)
@@ -72,12 +74,12 @@ type PodEvent struct {
// PgUser contains information about a single user.
type PgUser struct {
Origin RoleOrigin
Name string
Password string
Flags []string
MemberOf []string
Parameters map[string]string
Origin RoleOrigin `yaml:"-"`
Name string `yaml:"-"`
Password string `yaml:"-"`
Flags []string `yaml:"user_flags"`
MemberOf []string `yaml:"inrole"`
Parameters map[string]string `yaml:"db_parameters"`
}
// PgUserMap maps user names to the definitions.
@@ -203,6 +205,20 @@ func (n *NamespacedName) DecodeWorker(value, operatorNamespace string) error {
return nil
}
func (r RoleOrigin) String() string {
switch r {
case RoleOriginManifest:
return "manifest role"
case RoleOriginInfrastructure:
return "infrastructure role"
case RoleOriginTeamsAPI:
return "teams API role"
case RoleOriginSystem:
return "system role"
}
return "unknown"
}
// GetOperatorNamespace assumes serviceaccount secret is mounted by kubernetes
// Placing this func here instead of pgk/util avoids circular import
func GetOperatorNamespace() string {