mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-09-30 08:58:11 +02:00
feat (operator): add support for IRSA (aws resources access) (#3128)
* fix data to POSIX and sed working on macos * add ServiceAccountGetter to the newFakeK8sAnnotationsClient for unit tests * try to update the service account * use irsa_role_arn since we need the full arn, and remove enable_irsa * move sa sync code to existing sync.go file to be all together * change all Irsa to IRSA to follow go idiomatic that capitalize initialisms or acronyms * using Update instead of Patch for the service account syn * document the new option and add the key in the values/configs * add the new option to the administrator docs * trying to increase the timeout for the flaky test after sync --------- Co-authored-by: Felix Kunde <felix-kunde@gmx.de>
This commit is contained in:
co-authored by
Felix Kunde
parent
85d7aebab2
commit
7578f9d2c0
@@ -247,6 +247,12 @@ func (c *Controller) initPodServiceAccount() {
|
||||
c.PodServiceAccount.Name = c.opConfig.PodServiceAccountName
|
||||
}
|
||||
c.PodServiceAccount.Namespace = ""
|
||||
if c.opConfig.IRSARoleARN != "" {
|
||||
if c.PodServiceAccount.Annotations == nil {
|
||||
c.PodServiceAccount.Annotations = make(map[string]string)
|
||||
}
|
||||
c.PodServiceAccount.Annotations[constants.IRSAAnnotation] = c.opConfig.IRSARoleARN
|
||||
}
|
||||
}
|
||||
|
||||
// actual service accounts are deployed at the time of Postgres/Spilo cluster creation
|
||||
|
||||
@@ -175,6 +175,7 @@ func (c *Controller) importConfigurationFromCRD(fromCRD *acidv1.OperatorConfigur
|
||||
result.AWSRegion = fromCRD.AWSGCP.AWSRegion
|
||||
result.LogS3Bucket = fromCRD.AWSGCP.LogS3Bucket
|
||||
result.KubeIAMRole = fromCRD.AWSGCP.KubeIAMRole
|
||||
result.IRSARoleARN = fromCRD.AWSGCP.IRSARoleARN
|
||||
result.WALGSBucket = fromCRD.AWSGCP.WALGSBucket
|
||||
result.GCPCredentials = fromCRD.AWSGCP.GCPCredentials
|
||||
result.WALAZStorageAccount = fromCRD.AWSGCP.WALAZStorageAccount
|
||||
|
||||
Reference in New Issue
Block a user