Look for secrets in the deployed namespace

This commit is contained in:
Sergey Dudoladov
2018-02-14 15:37:30 +01:00
parent 5837015b3c
commit d5d15b7546
4 changed files with 50 additions and 21 deletions
+13 -6
View File
@@ -105,15 +105,10 @@ func (c *Controller) initOperatorConfig() {
}
if configMapData["watched_namespace"] == "" {
c.logger.Infof("No namespace to watch specified. By convention, the operator falls back to watching the namespace it is deployed to: '%v' \n", c.config.Namespace)
c.logger.Infof("No namespace to watch specified. By convention, the operator falls back to watching the namespace it is deployed to: '%v' \n", c.config.Namespace)
configMapData["watched_namespace"] = c.config.Namespace
}
_, err := c.KubeClient.ServiceAccounts(configMapData["watched_namespace"]).Get("operator", metav1.GetOptions{})
if err != nil {
c.logger.Warnf("Cannot find the 'operator' service account in the watched namepsace %q. Pods will not be able to start. Error: %v", c.opConfig.WatchedNamespace, err)
}
if c.config.NoDatabaseAccess {
configMapData["enable_database_access"] = "false"
}
@@ -136,6 +131,11 @@ func (c *Controller) initController() {
c.logger.Infof("config: %s", c.opConfig.MustMarshal())
c.mustHaveOperatorServiceAccountInNamespace(c.config.Namespace)
if c.config.Namespace != c.opConfig.WatchedNamespace {
c.mustHaveOperatorServiceAccountInNamespace(c.opConfig.WatchedNamespace)
}
if c.opConfig.DebugLogging {
c.logger.Logger.Level = logrus.DebugLevel
}
@@ -261,3 +261,10 @@ func (c *Controller) kubeNodesInformer(stopCh <-chan struct{}, wg *sync.WaitGrou
c.nodesInformer.Run(stopCh)
}
func (c *Controller) mustHaveOperatorServiceAccountInNamespace(namespace string) {
_, err := c.KubeClient.ServiceAccounts(namespace).Get(c.opConfig.ServiceAccountName, metav1.GetOptions{})
if err != nil {
c.logger.Warnf("Cannot find the '%v' service account in the namepsace %q. Pods will not be able to start. Error: %v", c.opConfig.ServiceAccountName, namespace, err)
}
}