update individual role secrets from infrastructure roles (#206)

* Track origin of roles.

* Propagate changes on infrastructure roles to corresponding secrets.

When the password in the infrastructure role is updated, re-generate the
secret for that role.

Previously, the password for an infrastructure role was always fetched from
the secret, making any updates to such role a no-op after the corresponding
secret had been generated.
This commit is contained in:
Oleksii Kliukin
2018-02-23 17:24:04 +01:00
committed by GitHub
parent 7b05758893
commit 2bb7e98268
7 changed files with 44 additions and 9 deletions
+11
View File
@@ -32,6 +32,16 @@ const (
fileWithNamespace = "/var/run/secrets/kubernetes.io/serviceaccount/namespace"
)
type RoleOrigin int
const (
RoleOriginUnknown = iota
RoleOriginInfrastructure
RoleOriginManifest
RoleOriginTeamsAPI
RoleOriginSystem
)
// ClusterEvent carries the payload of the Cluster TPR events.
type ClusterEvent struct {
EventTime time.Time
@@ -62,6 +72,7 @@ type PodEvent struct {
// PgUser contains information about a single user.
type PgUser struct {
Origin RoleOrigin
Name string
Password string
Flags []string