mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-01 05:14:47 +02:00
Look for secrets in the deployed namespace
This commit is contained in:
@@ -105,15 +105,10 @@ func (c *Controller) initOperatorConfig() {
|
||||
}
|
||||
|
||||
if configMapData["watched_namespace"] == "" {
|
||||
c.logger.Infof("No namespace to watch specified. By convention, the operator falls back to watching the namespace it is deployed to: '%v' \n", c.config.Namespace)
|
||||
c.logger.Infof("No namespace to watch specified. By convention, the operator falls back to watching the namespace it is deployed to: '%v' \n", c.config.Namespace)
|
||||
configMapData["watched_namespace"] = c.config.Namespace
|
||||
}
|
||||
|
||||
_, err := c.KubeClient.ServiceAccounts(configMapData["watched_namespace"]).Get("operator", metav1.GetOptions{})
|
||||
if err != nil {
|
||||
c.logger.Warnf("Cannot find the 'operator' service account in the watched namepsace %q. Pods will not be able to start. Error: %v", c.opConfig.WatchedNamespace, err)
|
||||
}
|
||||
|
||||
if c.config.NoDatabaseAccess {
|
||||
configMapData["enable_database_access"] = "false"
|
||||
}
|
||||
@@ -136,6 +131,11 @@ func (c *Controller) initController() {
|
||||
|
||||
c.logger.Infof("config: %s", c.opConfig.MustMarshal())
|
||||
|
||||
c.mustHaveOperatorServiceAccountInNamespace(c.config.Namespace)
|
||||
if c.config.Namespace != c.opConfig.WatchedNamespace {
|
||||
c.mustHaveOperatorServiceAccountInNamespace(c.opConfig.WatchedNamespace)
|
||||
}
|
||||
|
||||
if c.opConfig.DebugLogging {
|
||||
c.logger.Logger.Level = logrus.DebugLevel
|
||||
}
|
||||
@@ -261,3 +261,10 @@ func (c *Controller) kubeNodesInformer(stopCh <-chan struct{}, wg *sync.WaitGrou
|
||||
|
||||
c.nodesInformer.Run(stopCh)
|
||||
}
|
||||
|
||||
func (c *Controller) mustHaveOperatorServiceAccountInNamespace(namespace string) {
|
||||
_, err := c.KubeClient.ServiceAccounts(namespace).Get(c.opConfig.ServiceAccountName, metav1.GetOptions{})
|
||||
if err != nil {
|
||||
c.logger.Warnf("Cannot find the '%v' service account in the namepsace %q. Pods will not be able to start. Error: %v", c.opConfig.ServiceAccountName, namespace, err)
|
||||
}
|
||||
}
|
||||
|
||||
+19
-3
@@ -3,6 +3,8 @@ package spec
|
||||
import (
|
||||
"database/sql"
|
||||
"fmt"
|
||||
"io/ioutil"
|
||||
"log"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
@@ -26,6 +28,8 @@ const (
|
||||
EventUpdate EventType = "UPDATE"
|
||||
EventDelete EventType = "DELETE"
|
||||
EventSync EventType = "SYNC"
|
||||
|
||||
fileWithNamespace = "/var/run/secrets/kubernetes.io/serviceaccount/namespace"
|
||||
)
|
||||
|
||||
// ClusterEvent carries the payload of the Cluster TPR events.
|
||||
@@ -165,16 +169,28 @@ func (n *NamespacedName) Decode(value string) error {
|
||||
|
||||
if strings.Trim(value, string(types.Separator)) != "" && name == (types.NamespacedName{}) {
|
||||
name.Name = value
|
||||
name.Namespace = v1.NamespaceDefault
|
||||
name.Namespace = GetOperatorNamespace()
|
||||
} else if name.Namespace == "" {
|
||||
name.Namespace = v1.NamespaceDefault
|
||||
name.Namespace = GetOperatorNamespace()
|
||||
}
|
||||
|
||||
if name.Name == "" {
|
||||
return fmt.Errorf("incorrect namespaced name")
|
||||
return fmt.Errorf("incorrect namespaced name: %v", value)
|
||||
}
|
||||
|
||||
*n = NamespacedName(name)
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// GetOperatorNamespace assumes serviceaccount secret is mounted by kubernetes
|
||||
// Placing this func here instead of pgk/util avoids circular import
|
||||
func GetOperatorNamespace() string {
|
||||
|
||||
operatorNamespaceBytes, err := ioutil.ReadFile(fileWithNamespace)
|
||||
if err != nil {
|
||||
log.Fatalf("Unable to detect operator namespace from within its pod due to: %v", err)
|
||||
}
|
||||
|
||||
return string(operatorNamespaceBytes)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user