Skip to content

Commit

Permalink
issue-439, implemented opensearch user resource
Browse files Browse the repository at this point in the history
  • Loading branch information
worryg0d committed Jun 27, 2023
1 parent 1c7fd8d commit a5e31cb
Show file tree
Hide file tree
Showing 16 changed files with 734 additions and 2 deletions.
73 changes: 73 additions & 0 deletions apis/clusterresources/v1alpha1/opensearchuser_types.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
/*
Copyright 2023.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

package v1alpha1

import (
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
"sigs.k8s.io/controller-runtime/pkg/client"

"github.com/instaclustr/operator/pkg/models"
)

// OpenSearchUserSpec defines the desired state of OpenSearchUser
type OpenSearchUserSpec struct {
SecretRef *SecretReference `json:"secretRef"`
}

// OpenSearchUserStatus defines the observed state of OpenSearchUser
type OpenSearchUserStatus struct {
State string `json:"state"`
ClusterID string `json:"clusterId"`
}

//+kubebuilder:object:root=true
//+kubebuilder:subresource:status

// OpenSearchUser is the Schema for the opensearchusers API
type OpenSearchUser struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`

Spec OpenSearchUserSpec `json:"spec,omitempty"`
Status OpenSearchUserStatus `json:"status,omitempty"`
}

//+kubebuilder:object:root=true

// OpenSearchUserList contains a list of OpenSearchUser
type OpenSearchUserList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []OpenSearchUser `json:"items"`
}

func (u *OpenSearchUser) ToInstaAPI(username, password string) *models.InstaUser {
return &models.InstaUser{
Username: username,
Password: password,
InitialPermission: "standard",
}
}

func (u *OpenSearchUser) NewPatch() client.Patch {
old := u.DeepCopy()
return client.MergeFrom(old)
}

func init() {
SchemeBuilder.Register(&OpenSearchUser{}, &OpenSearchUserList{})
}
94 changes: 94 additions & 0 deletions apis/clusterresources/v1alpha1/zz_generated.deepcopy.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions apis/clusters/v1alpha1/opensearch_types.go
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,7 @@ type OpenSearchSpec struct {
IndexManagementPlugin bool `json:"indexManagementPlugin,omitempty"`
AlertingPlugin bool `json:"alertingPlugin,omitempty"`
BundledUseOnly bool `json:"bundleUseOnly,omitempty"`
UserRef *UserReference `json:"userRef,omitempty"`
}

type OpenSearchDataCentre struct {
Expand Down
5 changes: 5 additions & 0 deletions apis/clusters/v1alpha1/zz_generated.deepcopy.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.9.2
creationTimestamp: null
name: opensearchusers.clusterresources.instaclustr.com
spec:
group: clusterresources.instaclustr.com
names:
kind: OpenSearchUser
listKind: OpenSearchUserList
plural: opensearchusers
singular: opensearchuser
scope: Namespaced
versions:
- name: v1alpha1
schema:
openAPIV3Schema:
description: OpenSearchUser is the Schema for the opensearchusers API
properties:
apiVersion:
description: 'APIVersion defines the versioned schema of this representation
of an object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
type: string
kind:
description: 'Kind is a string value representing the REST resource this
object represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
type: string
metadata:
type: object
spec:
description: OpenSearchUserSpec defines the desired state of OpenSearchUser
properties:
secretRef:
properties:
name:
type: string
namespace:
type: string
required:
- name
- namespace
type: object
required:
- secretRef
type: object
status:
description: OpenSearchUserStatus defines the observed state of OpenSearchUser
properties:
clusterId:
type: string
state:
type: string
required:
- clusterId
- state
type: object
type: object
served: true
storage: true
subresources:
status: {}
10 changes: 10 additions & 0 deletions config/crd/bases/clusters.instaclustr.com_opensearches.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -212,6 +212,16 @@ spec:
- email
type: object
type: array
userRef:
properties:
name:
type: string
namespace:
type: string
required:
- name
- namespace
type: object
version:
type: string
required:
Expand Down
1 change: 1 addition & 0 deletions config/crd/kustomization.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@ resources:
- bases/clusterresources.instaclustr.com_redisusers.yaml
- bases/clusterresources.instaclustr.com_awsencryptionkeys.yaml
- bases/clusterresources.instaclustr.com_cassandrausers.yaml
- bases/clusterresources.instaclustr.com_opensearchusers.yaml
#+kubebuilder:scaffold:crdkustomizeresource

patchesStrategicMerge:
Expand Down
26 changes: 26 additions & 0 deletions config/rbac/role.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -309,6 +309,32 @@ rules:
- get
- patch
- update
- apiGroups:
- clusterresources.instaclustr.com
resources:
- opensearchusers
verbs:
- create
- delete
- get
- list
- patch
- update
- watch
- apiGroups:
- clusterresources.instaclustr.com
resources:
- opensearchusers/finalizers
verbs:
- update
- apiGroups:
- clusterresources.instaclustr.com
resources:
- opensearchusers/status
verbs:
- get
- patch
- update
- apiGroups:
- clusterresources.instaclustr.com
resources:
Expand Down
20 changes: 20 additions & 0 deletions config/samples/clusterresources_v1alpha1_opensearchuser.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
apiVersion: v1
kind: Secret
metadata:
name: test-secret-1
data:
username: dGVzdC11c2VyLTEK # test-user-1
password: VGVzdFBhc3MxMjMhCg== # TestPass123!
---
apiVersion: clusterresources.instaclustr.com/v1alpha1
kind: OpenSearchUser
metadata:
name: test-user-1
spec:
secretRef:
name: "test-secret-1"
namespace: "default"
# one of [standard, read-only, none]
# initialPermissions: "standard"
# indexPattern: ""
# role: ""
7 changes: 5 additions & 2 deletions config/samples/clusters_v1alpha1_opensearch.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,9 @@ spec:
alertingPlugin: false
anomalyDetectionPlugin: false
asynchronousSearchPlugin: false
userRef:
name: "test-user-1"
namespace: "default"
clusterManagerNodes:
- dedicatedManager: false
nodeSize: SRH-DEV-t4g.small-5
Expand All @@ -31,13 +34,13 @@ spec:
indexManagementPlugin: true
knnPlugin: false
loadBalancer: false
name: operatorOpenSearch
name: bohdan-test
notificationsPlugin: false
# opensearchDashboards:
# - nodeSize: SRH-DEV-t4g.small-5
# oidcProvider: ''
# version: opensearch-dashboards:2.5.0
version: 2.5.0
version: 2.7.0
pciCompliance: false
privateNetworkCluster: false
reportingPlugin: false
Expand Down
14 changes: 14 additions & 0 deletions controllers/clusterresources/helpers.go
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,10 @@ limitations under the License.
package clusterresources

import (
k8sCore "k8s.io/api/core/v1"

"github.com/instaclustr/operator/apis/clusterresources/v1alpha1"
"github.com/instaclustr/operator/pkg/models"
)

func areFirewallRuleStatusesEqual(a, b *v1alpha1.FirewallRuleStatus) bool {
Expand Down Expand Up @@ -61,3 +64,14 @@ func areEncryptionKeyStatusesEqual(a, b *v1alpha1.AWSEncryptionKeyStatus) bool {

return true
}

func getUserCreds(secret *k8sCore.Secret) (username, password string, err error) {
password = string(secret.Data["password"])
username = string(secret.Data["username"])

if len(username) == 0 || len(password) == 0 {
return "", "", models.ErrMissingSecretKeys
}

return username[:len(username)-1], password[:len(password)-1], nil
}
Loading

0 comments on commit a5e31cb

Please sign in to comment.