Schema: Add schema for role+access policies (#68047)

This commit is contained in:
Ryan McKinley
2023-05-24 10:31:57 -07:00
committed by GitHub
parent 3af95bebe1
commit e7da2a179e
34 changed files with 1863 additions and 4 deletions
+22
View File
@@ -7,6 +7,17 @@
//
// Run 'make gen-cue' from repository root to regenerate.
// Raw generated types from AccessPolicy kind.
export type {
AccessPolicy,
RoleRef,
ResourceRef,
AccessRule
} from './raw/accesspolicy/x/accesspolicy_types.gen';
// Raw generated enums and default consts from accesspolicy kind.
export { defaultAccessPolicy } from './raw/accesspolicy/x/accesspolicy_types.gen';
// Raw generated types from Dashboard kind.
export type {
AnnotationTarget,
@@ -129,6 +140,17 @@ export type {
// Raw generated types from PublicDashboard kind.
export type { PublicDashboard } from './raw/publicdashboard/x/publicdashboard_types.gen';
// Raw generated types from Role kind.
export type { Role } from './raw/role/x/role_types.gen';
// Raw generated types from RoleBinding kind.
export type {
RoleBinding,
CustomRoleRef,
BuiltinRoleRef,
RoleBindingSubject
} from './raw/rolebinding/x/rolebinding_types.gen';
// Raw generated types from ServiceAccount kind.
export type {
ServiceAccount,
@@ -0,0 +1,60 @@
// Code generated - EDITING IS FUTILE. DO NOT EDIT.
//
// Generated by:
// kinds/gen.go
// Using jennies:
// TSResourceJenny
// LatestMajorsOrXJenny
//
// Run 'make gen-cue' from repository root to regenerate.
export interface RoleRef {
/**
* Policies can apply to roles, teams, or users
* Applying policies to individual users is supported, but discouraged
*/
kind: ('Role' | 'BuiltinRole' | 'Team' | 'User');
name: string;
xname: string; // temporary
}
export interface ResourceRef {
kind: string; // explicit resource or folder will cascade
name: string;
}
export interface AccessRule {
/**
* The kind this rule applies to (dashboars, alert, etc)
*/
kind: ('*' | string);
/**
* Specific sub-elements like "alert.rules" or "dashboard.permissions"????
*/
target?: string;
/**
* READ, WRITE, CREATE, DELETE, ...
* should move to k8s style verbs like: "get", "list", "watch", "create", "update", "patch", "delete"
*/
verb: ('*' | 'none' | string);
}
export interface AccessPolicy {
/**
* The role that must apply this policy
*/
role: RoleRef;
/**
* The set of rules to apply. Note that * is required to modify
* access policy rules, and that "none" will reject all actions
*/
rules: Array<AccessRule>;
/**
* The scope where these policies should apply
*/
scope: ResourceRef;
}
export const defaultAccessPolicy: Partial<AccessPolicy> = {
rules: [],
};
@@ -0,0 +1,32 @@
// Code generated - EDITING IS FUTILE. DO NOT EDIT.
//
// Generated by:
// kinds/gen.go
// Using jennies:
// TSResourceJenny
// LatestMajorsOrXJenny
//
// Run 'make gen-cue' from repository root to regenerate.
export interface Role {
/**
* Role description
*/
description?: string;
/**
* Optional display
*/
displayName?: string;
/**
* Name of the team.
*/
groupName?: string;
/**
* Do not show this role
*/
hidden: (boolean | false);
/**
* The role identifier `managed:builtins:editor:permissions`
*/
name: string;
}
@@ -0,0 +1,38 @@
// Code generated - EDITING IS FUTILE. DO NOT EDIT.
//
// Generated by:
// kinds/gen.go
// Using jennies:
// TSResourceJenny
// LatestMajorsOrXJenny
//
// Run 'make gen-cue' from repository root to regenerate.
export interface CustomRoleRef {
kind: 'Role';
name: string;
}
export interface BuiltinRoleRef {
kind: 'BuiltinRole';
name: ('viewer' | 'editor' | 'admin');
}
export interface RoleBindingSubject {
kind: ('Team' | 'User');
/**
* The team/user identifier name
*/
name: string;
}
export interface RoleBinding {
/**
* The role we are discussing
*/
role: (BuiltinRoleRef | CustomRoleRef);
/**
* The team or user that has the specified role
*/
subject: RoleBindingSubject;
}