Zanzana: reconcile basic roles and bindings (#96473)
* Add reconciler for basic roles * Add reconciler for basic role bindings
This commit is contained in:
@@ -5,6 +5,22 @@ import (
|
||||
folderalpha1 "github.com/grafana/grafana/pkg/apis/folder/v0alpha1"
|
||||
)
|
||||
|
||||
const (
|
||||
roleGrafanaAdmin = "Grafana Admin"
|
||||
roleAdmin = "Admin"
|
||||
roleEditor = "Editor"
|
||||
roleViewer = "Viewer"
|
||||
roleNone = "None"
|
||||
)
|
||||
|
||||
var basicRolesTranslations = map[string]string{
|
||||
roleGrafanaAdmin: "basic_grafana_admin",
|
||||
roleAdmin: "basic_admin",
|
||||
roleEditor: "basic_editor",
|
||||
roleViewer: "basic_viewer",
|
||||
roleNone: "basic_none",
|
||||
}
|
||||
|
||||
type resourceTranslation struct {
|
||||
typ string
|
||||
group string
|
||||
|
||||
@@ -73,19 +73,6 @@ const (
|
||||
KindFolders string = "folders"
|
||||
)
|
||||
|
||||
const (
|
||||
RoleGrafanaAdmin = "Grafana Admin"
|
||||
RoleAdmin = "Admin"
|
||||
RoleEditor = "Editor"
|
||||
RoleViewer = "Viewer"
|
||||
RoleNone = "None"
|
||||
|
||||
BasicRolePrefix = "basic:"
|
||||
BasicRoleUIDPrefix = "basic_"
|
||||
|
||||
GlobalOrgID = 0
|
||||
)
|
||||
|
||||
var (
|
||||
ToAuthzExtTupleKey = common.ToAuthzExtTupleKey
|
||||
ToAuthzExtTupleKeys = common.ToAuthzExtTupleKeys
|
||||
@@ -98,11 +85,11 @@ var (
|
||||
ToOpenFGATupleKeyWithoutCondition = common.ToOpenFGATupleKeyWithoutCondition
|
||||
)
|
||||
|
||||
// NewTupleEntry constructs new openfga entry type:id[#relation].
|
||||
// Relation allows to specify group of users (subjects) related to type:id
|
||||
// NewTupleEntry constructs new openfga entry type:name[#relation].
|
||||
// Relation allows to specify group of users (subjects) related to type:name
|
||||
// (for example, team:devs#member refers to users which are members of team devs)
|
||||
func NewTupleEntry(objectType, id, relation string) string {
|
||||
obj := fmt.Sprintf("%s:%s", objectType, id)
|
||||
func NewTupleEntry(objectType, name, relation string) string {
|
||||
obj := fmt.Sprintf("%s:%s", objectType, name)
|
||||
if relation != "" {
|
||||
obj = fmt.Sprintf("%s#%s", obj, relation)
|
||||
}
|
||||
@@ -121,6 +108,10 @@ func TranslateToResourceTuple(subject string, action, kind, name string) (*openf
|
||||
return nil, false
|
||||
}
|
||||
|
||||
if name == "*" {
|
||||
return common.NewNamespaceResourceTuple(subject, m.relation, translation.group, translation.resource), true
|
||||
}
|
||||
|
||||
if translation.typ == TypeResource {
|
||||
return common.NewResourceTuple(subject, m.relation, translation.group, translation.resource, name), true
|
||||
}
|
||||
@@ -174,3 +165,7 @@ func TranslateToCheckRequest(namespace, action, kind, folder, name string) (*aut
|
||||
|
||||
return req, true
|
||||
}
|
||||
|
||||
func TranslateBasicRole(name string) string {
|
||||
return basicRolesTranslations[name]
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user