Look for secrets in the deployed namespace

This commit is contained in:
Sergey Dudoladov
2018-02-14 15:37:30 +01:00
parent 5837015b3c
commit d5d15b7546
4 changed files with 50 additions and 21 deletions
+13 -6
View File
@@ -105,15 +105,10 @@ func (c *Controller) initOperatorConfig() {
}
if configMapData["watched_namespace"] == "" {
c.logger.Infof("No namespace to watch specified. By convention, the operator falls back to watching the namespace it is deployed to: '%v' \n", c.config.Namespace)
c.logger.Infof("No namespace to watch specified. By convention, the operator falls back to watching the namespace it is deployed to: '%v' \n", c.config.Namespace)
configMapData["watched_namespace"] = c.config.Namespace
}
_, err := c.KubeClient.ServiceAccounts(configMapData["watched_namespace"]).Get("operator", metav1.GetOptions{})
if err != nil {
c.logger.Warnf("Cannot find the 'operator' service account in the watched namepsace %q. Pods will not be able to start. Error: %v", c.opConfig.WatchedNamespace, err)
}
if c.config.NoDatabaseAccess {
configMapData["enable_database_access"] = "false"
}
@@ -136,6 +131,11 @@ func (c *Controller) initController() {
c.logger.Infof("config: %s", c.opConfig.MustMarshal())
c.mustHaveOperatorServiceAccountInNamespace(c.config.Namespace)
if c.config.Namespace != c.opConfig.WatchedNamespace {
c.mustHaveOperatorServiceAccountInNamespace(c.opConfig.WatchedNamespace)
}
if c.opConfig.DebugLogging {
c.logger.Logger.Level = logrus.DebugLevel
}
@@ -261,3 +261,10 @@ func (c *Controller) kubeNodesInformer(stopCh <-chan struct{}, wg *sync.WaitGrou
c.nodesInformer.Run(stopCh)
}
func (c *Controller) mustHaveOperatorServiceAccountInNamespace(namespace string) {
_, err := c.KubeClient.ServiceAccounts(namespace).Get(c.opConfig.ServiceAccountName, metav1.GetOptions{})
if err != nil {
c.logger.Warnf("Cannot find the '%v' service account in the namepsace %q. Pods will not be able to start. Error: %v", c.opConfig.ServiceAccountName, namespace, err)
}
}
+19 -3
View File
@@ -3,6 +3,8 @@ package spec
import (
"database/sql"
"fmt"
"io/ioutil"
"log"
"strings"
"time"
@@ -26,6 +28,8 @@ const (
EventUpdate EventType = "UPDATE"
EventDelete EventType = "DELETE"
EventSync EventType = "SYNC"
fileWithNamespace = "/var/run/secrets/kubernetes.io/serviceaccount/namespace"
)
// ClusterEvent carries the payload of the Cluster TPR events.
@@ -165,16 +169,28 @@ func (n *NamespacedName) Decode(value string) error {
if strings.Trim(value, string(types.Separator)) != "" && name == (types.NamespacedName{}) {
name.Name = value
name.Namespace = v1.NamespaceDefault
name.Namespace = GetOperatorNamespace()
} else if name.Namespace == "" {
name.Namespace = v1.NamespaceDefault
name.Namespace = GetOperatorNamespace()
}
if name.Name == "" {
return fmt.Errorf("incorrect namespaced name")
return fmt.Errorf("incorrect namespaced name: %v", value)
}
*n = NamespacedName(name)
return nil
}
// GetOperatorNamespace assumes serviceaccount secret is mounted by kubernetes
// Placing this func here instead of pgk/util avoids circular import
func GetOperatorNamespace() string {
operatorNamespaceBytes, err := ioutil.ReadFile(fileWithNamespace)
if err != nil {
log.Fatalf("Unable to detect operator namespace from within its pod due to: %v", err)
}
return string(operatorNamespaceBytes)
}