K8s/ManagedBy: Enforce who can CRUD provisioning resources (#103322)

This commit is contained in:
Ryan McKinley
2025-04-08 14:17:33 +03:00
committed by GitHub
parent 577ea8f6a9
commit d3e6e308a0
8 changed files with 290 additions and 8 deletions
+8
View File
@@ -61,6 +61,9 @@ func (s *Storage) prepareObjectForStorage(ctx context.Context, newObject runtime
if obj.GetFolder() != "" && !s.opts.EnableFolderSupport {
return nil, apierrors.NewBadRequest(fmt.Sprintf("folders are not supported for: %s", s.gr.String()))
}
if err := checkManagerPropertiesOnCreate(info, obj); err != nil {
return nil, err
}
if s.opts.RequireDeprecatedInternalID {
// nolint:staticcheck
@@ -160,6 +163,11 @@ func (s *Storage) prepareObjectForUpdate(ctx context.Context, updateObject runti
obj.SetGeneration(previous.GetGeneration() + 1)
obj.SetUpdatedBy(info.GetUID())
obj.SetUpdatedTimestampMillis(time.Now().UnixMilli())
// Only validate when the generation has changed
if err := checkManagerPropertiesOnUpdateSpec(info, obj, previous); err != nil {
return nil, err
}
} else {
obj.SetGeneration(previous.GetGeneration())
obj.SetAnnotation(utils.AnnoKeyUpdatedBy, previous.GetAnnotation(utils.AnnoKeyUpdatedBy))