Zanzana: Use separate store for each org (#96015)

* Move server init into server package

* map store name to id

* refactor model loading

* pass namespace into reconcilers and collectors

* refactor

* Extend authz server with Read and Write methods

* use new read/write in reconciler

* implement server side read and write

* Sync permissions for every org

* handle namespace in check and list

* split read and write

* provide conditions

* Fix client implementation

* fix nil conditions

* remove unused client code

* use lock for store access

* move type translators to common package

* fix folder collector

* fix store creation

* remove unused AuthorizationModelId

* fix server tests

* fix linter
This commit is contained in:
Alexander Zobnin
2024-11-08 14:54:36 +01:00
committed by GitHub
parent 86bc087257
commit 910ec7e7dc
22 changed files with 1497 additions and 396 deletions
@@ -0,0 +1,47 @@
package server
import (
"context"
openfgav1 "github.com/openfga/api/proto/openfga/v1"
"github.com/grafana/grafana/pkg/services/authz/zanzana/common"
authzextv1 "github.com/grafana/grafana/pkg/services/authz/zanzana/proto/v1"
)
func (s *Server) Read(ctx context.Context, req *authzextv1.ReadRequest) (*authzextv1.ReadResponse, error) {
ctx, span := tracer.Start(ctx, "authzServer.Read")
defer span.End()
storeInf, err := s.getNamespaceStore(ctx, req.Namespace)
if err != nil {
return nil, err
}
res, err := s.openfga.Read(ctx, &openfgav1.ReadRequest{
StoreId: storeInf.Id,
TupleKey: &openfgav1.ReadRequestTupleKey{
User: req.GetTupleKey().GetUser(),
Relation: req.GetTupleKey().GetRelation(),
Object: req.GetTupleKey().GetObject(),
},
PageSize: req.GetPageSize(),
ContinuationToken: req.GetContinuationToken(),
})
if err != nil {
return nil, err
}
tuples := make([]*authzextv1.Tuple, 0)
for _, t := range res.GetTuples() {
tuples = append(tuples, &authzextv1.Tuple{
Key: common.ToAuthzExtTupleKey(t.GetKey()),
Timestamp: t.GetTimestamp(),
})
}
return &authzextv1.ReadResponse{
Tuples: tuples,
ContinuationToken: res.GetContinuationToken(),
}, nil
}