Access Control: Add fixed role loader service (#112747)

This commit is contained in:
Todd Treece
2025-10-22 12:04:42 -04:00
committed by GitHub
parent 13f44336f2
commit 638a1808f8
11 changed files with 96 additions and 19 deletions
@@ -0,0 +1,57 @@
package accesscontrol
import (
"context"
"github.com/grafana/dskit/services"
"github.com/grafana/grafana/pkg/infra/log"
"github.com/grafana/grafana/pkg/services/featuremgmt"
)
const FixedRolesLoaderServiceName = "accesscontrol.fixedrolesloader"
type FixedRolesLoader struct {
services.NamedService
roleRegistry RoleRegistry
features featuremgmt.FeatureToggles
log log.Logger
}
func ProvideFixedRolesLoader(roleRegistry RoleRegistry, features featuremgmt.FeatureToggles) *FixedRolesLoader {
loader := &FixedRolesLoader{
roleRegistry: roleRegistry,
features: features,
log: log.New(FixedRolesLoaderServiceName),
}
loader.NamedService = services.NewBasicService(loader.starting, loader.running, nil).WithName(FixedRolesLoaderServiceName)
return loader
}
func (l *FixedRolesLoader) starting(ctx context.Context) error {
ctxLogger := l.log.FromContext(ctx)
ctxLogger.Debug("Registering fixed roles")
if err := l.roleRegistry.RegisterFixedRoles(ctx); err != nil {
ctxLogger.Error("Failed to register fixed roles", "error", err)
return err
}
return nil
}
func (l *FixedRolesLoader) running(ctx context.Context) error {
<-ctx.Done()
return nil
}
func (l *FixedRolesLoader) IsDisabled() bool {
return !l.features.IsEnabledGlobally(featuremgmt.FlagPluginStoreServiceLoading)
}
func (l *FixedRolesLoader) Run(ctx context.Context) error {
<-ctx.Done()
return nil
}
+1 -1
View File
@@ -2128,7 +2128,7 @@ var (
},
{
Name: "pluginStoreServiceLoading",
Description: "Load plugins during store service startup instead of wire provider",
Description: "Load plugins on store service startup instead of wire provider, and call RegisterFixedRoles after all plugins are loaded",
Stage: FeatureStageExperimental,
FrontendOnly: false,
Owner: grafanaPluginsPlatformSquad,
+1 -1
View File
@@ -1103,7 +1103,7 @@ const (
FlagPreventPanelChromeOverflow = "preventPanelChromeOverflow"
// FlagPluginStoreServiceLoading
// Load plugins during store service startup instead of wire provider
// Load plugins on store service startup instead of wire provider, and call RegisterFixedRoles after all plugins are loaded
FlagPluginStoreServiceLoading = "pluginStoreServiceLoading"
// FlagOnlyStoreActionSets
+6 -3
View File
@@ -2997,11 +2997,14 @@
{
"metadata": {
"name": "pluginStoreServiceLoading",
"resourceVersion": "1760712768362",
"creationTimestamp": "2025-10-17T14:52:48Z"
"resourceVersion": "1761144346944",
"creationTimestamp": "2025-10-17T14:52:48Z",
"annotations": {
"grafana.app/updatedTimestamp": "2025-10-22 14:45:46.944669 +0000 UTC"
}
},
"spec": {
"description": "Load plugins during store service startup instead of wire provider",
"description": "Load plugins on store service startup instead of wire provider, and call RegisterFixedRoles after all plugins are loaded",
"stage": "experimental",
"codeowner": "@grafana/plugins-platform-backend",
"expression": "false"