K8s/SecureValues: Wire InlineSecureValueSupport to apistore (#109449)

* inline wire

* extra fields

* add variable

* wire
This commit is contained in:
Ryan McKinley
2025-08-11 15:22:56 +03:00
committed by GitHub
parent 4682a288a3
commit e0404f924c
13 changed files with 245 additions and 191 deletions
+16 -4
View File
@@ -19,6 +19,7 @@ import (
flowcontrolrequest "k8s.io/apiserver/pkg/util/flowcontrol/request"
"k8s.io/client-go/tools/cache"
secret "github.com/grafana/grafana/pkg/registry/apis/secret/contracts"
"github.com/grafana/grafana/pkg/storage/unified/resource"
)
@@ -28,6 +29,7 @@ type StorageOptionsRegister func(gr schema.GroupResource, opts StorageOptions)
type RESTOptionsGetter struct {
client resource.ResourceClient
secrets secret.InlineSecureValueSupport
original storagebackend.Config
configProvider RestConfigProvider
@@ -35,16 +37,22 @@ type RESTOptionsGetter struct {
options map[string]StorageOptions
}
func NewRESTOptionsGetterForClient(client resource.ResourceClient, original storagebackend.Config, configProvider RestConfigProvider) *RESTOptionsGetter {
func NewRESTOptionsGetterForClient(
client resource.ResourceClient,
secrets secret.InlineSecureValueSupport,
original storagebackend.Config,
configProvider RestConfigProvider,
) *RESTOptionsGetter {
return &RESTOptionsGetter{
client: client,
secrets: secrets,
original: original,
options: make(map[string]StorageOptions),
configProvider: configProvider,
}
}
func NewRESTOptionsGetterMemory(originalStorageConfig storagebackend.Config) (*RESTOptionsGetter, error) {
func NewRESTOptionsGetterMemory(originalStorageConfig storagebackend.Config, secrets secret.InlineSecureValueSupport) (*RESTOptionsGetter, error) {
backend, err := resource.NewCDKBackend(context.Background(), resource.CDKBackendOptions{
Bucket: memblob.OpenBucket(&memblob.Options{}),
})
@@ -59,6 +67,7 @@ func NewRESTOptionsGetterMemory(originalStorageConfig storagebackend.Config) (*R
}
return NewRESTOptionsGetterForClient(
resource.NewLocalResourceClient(server),
secrets,
originalStorageConfig,
nil,
), nil
@@ -67,7 +76,7 @@ func NewRESTOptionsGetterMemory(originalStorageConfig storagebackend.Config) (*R
// Optionally, this constructor allows specifying directories
// for resources that are required to be read/watched on startup and there
// won't be any write operations that initially bootstrap their directories
func NewRESTOptionsGetterForFile(path string,
func NewRESTOptionsGetterForFileXX(path string,
originalStorageConfig storagebackend.Config,
features map[string]any) (*RESTOptionsGetter, error) {
if path == "" {
@@ -95,6 +104,7 @@ func NewRESTOptionsGetterForFile(path string,
}
return NewRESTOptionsGetterForClient(
resource.NewLocalResourceClient(server),
nil, // secrets
originalStorageConfig,
nil,
), nil
@@ -137,8 +147,10 @@ func (r *RESTOptionsGetter) GetRESTOptions(resource schema.GroupResource, _ runt
trigger storage.IndexerFuncs,
indexers *cache.Indexers,
) (storage.Interface, factory.DestroyFunc, error) {
opts := r.options[resource.String()]
opts.SecureValues = r.secrets
return NewStorage(config, r.client, keyFunc, nil, newFunc, newListFunc, getAttrsFunc,
trigger, indexers, r.configProvider, r.options[resource.String()])
trigger, indexers, r.configProvider, opts)
},
DeleteCollectionWorkers: 0,
EnableGarbageCollection: false,
+4 -1
View File
@@ -32,9 +32,9 @@ import (
"k8s.io/client-go/tools/cache"
authtypes "github.com/grafana/authlib/types"
"github.com/grafana/grafana/pkg/apimachinery/utils"
grafanaregistry "github.com/grafana/grafana/pkg/apiserver/registry/generic"
secrets "github.com/grafana/grafana/pkg/registry/apis/secret/contracts"
"github.com/grafana/grafana/pkg/storage/unified/resource"
"github.com/grafana/grafana/pkg/storage/unified/resourcepb"
)
@@ -61,6 +61,9 @@ type StorageOptions struct {
// Add internalID label when missing
RequireDeprecatedInternalID bool
// Process inline secure values
SecureValues secrets.InlineSecureValueSupport
// Temporary fix to support adding default permissions AfterCreate
Permissions DefaultPermissionSetter
}